@shared-web/constants@9.9.9
Malicious code in @shared-web/constants (npm)
Analysis
@shared-web/constants@9.9.9 is a dependency-confusion/version-squat stub: a scoped package published at the sentinel version 9.9.9 containing only a placeholder entrypoint (module.exports = {}) with no implementation, no repository, no documentation of real functionality, and no dependency tree. The README states the full implementation "ships in the next release." The scoped name combined with the high sentinel version number is positioned to be resolved by automated dependency resolution in place of a legitimate internal package. No executable payload is present in this version.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 09:03 AM
- analyzed
- Sep 18, 2026, 09:04 AM
Related advisories
- @shared-web/utils@9.9.10
- @shared-web/assets@9.9.10
- @shared-web/modules@9.9.9
- @shared-runtime/api@9.9.9
- @shared-web/tracking@9.9.9
- @shared-web/api@9.9.9
- @shared-runtime/config@9.9.9
- hardhat-devkit@2.3.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.