mm-ts-utils-client@99.9.1
Malicious code in mm-ts-utils-client (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
mm-ts-utils-client is a dependency-confusion supply-chain attack. The package is a bare stub (module.exports = {}; ~35 bytes) whose sole purpose is to pull an external dependency (ltidisafe) from hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-2[.]2[.]9[.]tgz. At install, a DNS resolution and HTTPS GET to that URL were observed before the tarball fetch failed (TAR_BAD_ARCHIVE). The dependency-confusion name/version scheme delivers remote payloads at install time.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 06:07 PM
- analyzed
- Jun 10, 2026, 06:08 PM
Related advisories
- mjs-biginteger@5.0.6
- websocket-slot@0.0.6
- metrica-node@2.4.5
- metrica-chain@2.4.5
- meowmeow111@1.0.0
- meowmeow11001@1.0.0
- prettier_v2@3.8.5
- win-build-utils@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.