@guildai-services/guildai@99.9.1
Malicious code in @guildai-services/guildai (npm)
Analysis
Dependency-confusion stub package. The package ships an empty module (module.exports = {}) with no code of its own, but declares a dependency "ltidisafe" that is fetched from a non-registry CDN rather than the npm registry: hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]7[.]7[.]tgz. Installing this package pulls and installs that off-registry tarball from the attacker-controlled Google Cloud Storage host, injecting an unvetted dependency into the install graph. The high version (99.9.1) on a scoped name is the dependency-confusion shape used to trick resolvers into preferring this package over a legitimate one.
- analyzed by
- Leitwacht
- first seen
- Aug 15, 2026, 04:28 PM
- analyzed
- Aug 15, 2026, 04:28 PM
Related advisories
- bs58-33@6.0.1
- @morpho-blue-liquidation-bot/data-providers@2.0.0
- @morpho-blue-liquidation-bot/pricers@2.0.0
- kepler@1.0.999
- test-flow-entire3@1.0.0
- testingflow2@1.0.0
- @queenanya/baileys@9.7.1
- @cr-invested-ui-components/chart@99.9.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.