LWA-2026-11334 confirmed malware

@guildai-services/guildai@99.9.1

Malicious code in @guildai-services/guildai (npm)

T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise

Analysis

Dependency-confusion stub package. The package ships an empty module (module.exports = {}) with no code of its own, but declares a dependency "ltidisafe" that is fetched from a non-registry CDN rather than the npm registry: hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]7[.]7[.]tgz. Installing this package pulls and installs that off-registry tarball from the attacker-controlled Google Cloud Storage host, injecting an unvetted dependency into the install graph. The high version (99.9.1) on a scoped name is the dependency-confusion shape used to trick resolvers into preferring this package over a legitimate one.

analyzed by
Leitwacht
first seen
Aug 15, 2026, 04:28 PM
analyzed
Aug 15, 2026, 04:28 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.