@shared-runtime/api@9.9.9
Malicious code in @shared-runtime/api (npm)
Analysis
Dependency-confusion squat: the scoped package @shared-runtime/api at version 9.9.9 presents itself as "Shared runtime API client utilities for internal microservices" — a name and description matching a private/internal package — but ships only an empty placeholder module (module.exports = {}) with no implementation. The high version number and internal-facing scoped name are designed to make a package manager resolve this attacker-controlled package instead of the legitimate internal one, hijacking the install. No lifecycle hooks or network activity are present in this version; the squat occupies the internal namespace and can be updated to a malicious payload.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 09:03 AM
- analyzed
- Sep 18, 2026, 09:04 AM
Related advisories
- @shared-runtime/modules@9.9.10
- @shared-runtime/config@9.9.9
- @shared-web/tracking@9.9.9
- @shared-web/api@9.9.9
- hardhat-devkit@2.3.6
- tailwindcss-form-utils@0.5.1
- tailwindcss-form-ui@0.5.1
- @vitemirrorte/element-plus-vite-cli@2.9.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.