@airbnb-extended/typescript-config@99.9.1
Malicious code in @airbnb-extended/typescript-config (npm)
Analysis
@airbnb-extended/typescript-config@99.9.1 is a version-squat stub impersonating Airbnb's TypeScript configuration package. The tarball contains only an empty index.js (module.exports = {}) with no functional code, but its package.json declares a dependency "ltidisafe" pinned to an off-registry Google Cloud Storage URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]7[.]8[.]tgz). Installing the package pulls and installs attacker-controlled code from this non-npm host, enabling arbitrary code execution on the installer's machine.
- analyzed by
- Leitwacht
- first seen
- Sep 25, 2026, 05:48 AM
- analyzed
- Sep 25, 2026, 05:49 AM
Related advisories
- selfsigned-generator@1.0.0
- wallet-connect-adapter@1.4.2
- n8n-nodes-flowstats@1.0.0
- simple-date-formatter-new-12@1.0.0
- n8n-nodes-moonlet-utils@1.0.0
- n8n-nodes-moonlet-helpers@1.0.0
- internallib_v463@1.0.2
- internallib_v657@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.