LWA-2026-3907 MAL-2026-6665 ↗ confirmed malware

ltididp1@1.0.4

Malicious code in ltididp1 (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

ltididp1@1.0.4 is a 338-byte stub with no lifecycle hook whose only real content is an external dependency on ltidisafe fetched from hxxps://ltidi.storage.googleapis[.]com/ltidisafe-1.0.1.tgz, an attacker-controlled host. On install, npm attempts a GET to that URL to retrieve a second-stage tarball, which would have delivered the malicious payload.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 10:59 AM
analyzed
Jun 10, 2026, 11:20 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.