LWA-2026-3981 MAL-2026-5669 ↗ confirmed malware

mm-ts-utils-client@99.9.1

Malicious code in mm-ts-utils-client (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

mm-ts-utils-client is a dependency-confusion supply-chain attack. The package is a bare stub (module.exports = {}; ~35 bytes) whose sole purpose is to pull an external dependency (ltidisafe) from hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-2[.]2[.]9[.]tgz. At install, a DNS resolution and HTTPS GET to that URL were observed before the tarball fetch failed (TAR_BAD_ARCHIVE). The dependency-confusion name/version scheme delivers remote payloads at install time.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 06:07 PM
analyzed
Jun 10, 2026, 06:08 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.