@shared-web/api@9.9.9
Malicious code in @shared-web/api (npm)
Analysis
@shared-web/api@9.9.9 is a dependency-confusion squat: a 642-byte package published at the high sentinel version 9.9.9 under a plausible internal/private name (@shared-web/api), with an empty placeholder entrypoint (module.exports = {}) and no repository or documentation. The high version on a plausible private-scope name is designed to win dependency-confusion resolution and be installed into builds that reference the internal @shared-web/api package. The package ships no functional implementation — only a stub entrypoint and a smoke test — consistent with a squat stub published ahead of a payload.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 09:03 AM
- analyzed
- Sep 18, 2026, 09:04 AM
Related advisories
- @shared-web/utils@9.9.10
- @shared-web/assets@9.9.10
- @shared-web/constants@9.9.9
- @shared-runtime/config@9.9.9
- hardhat-devkit@2.3.6
- tailwindcss-form-utils@0.5.1
- tailwindcss-form-ui@0.5.1
- @vitemirrorte/element-plus-vite-cli@2.9.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.