ltididp1@1.0.4
Malicious code in ltididp1 (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
ltididp1@1.0.4 is a 338-byte stub with no lifecycle hook whose only real content is an external dependency on ltidisafe fetched from hxxps://ltidi.storage.googleapis[.]com/ltidisafe-1.0.1.tgz, an attacker-controlled host. On install, npm attempts a GET to that URL to retrieve a second-stage tarball, which would have delivered the malicious payload.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 10:59 AM
- analyzed
- Jun 10, 2026, 11:20 AM
Related advisories
- ltididp1@1.0.0 same package
- prettier_v1@3.8.4
- vite-config-optimizer@1.1.4
- optional-cpu-features@1.0.3
- vemos-sdk@1.0.0
- chai-check-error@2.1.3
- db-xorma@1.0.2
- os-ulid-void@3.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.