firefly-utilities-helper@99.9.1
Malicious code in firefly-utilities-helper (npm)
T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise
Analysis
firefly-utilities-helper is a dependency-confusion carrier package. The package itself is an empty shell (index.js exports {}, ~359 bytes, no lifecycle hooks), but its only dependency is an off-registry HTTPS tarball at hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]0[.]6[.]tgz. At npm install time that attacker-controlled tarball is fetched and extracted; if it carries lifecycle hooks, arbitrary code executes. The package has zero functionality and exists solely to route the installer into an attacker-controlled archive.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 05:16 PM
- analyzed
- Jun 10, 2026, 05:17 PM
Related advisories
- optional-cpu-features@1.0.3
- @morpho-blue-liquidation-bot/data-providers@2.0.0
- @morpho-blue-liquidation-bot/pricers@2.0.0
- kepler@1.0.999
- test-flow-entire3@1.0.0
- testingflow2@1.0.0
- @queenanya/baileys@9.7.1
- @cr-invested-ui-components/chart@99.9.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.