LWA-2026-4206 MAL-2026-10146 ↗ confirmed malware

ng-search-api@99.9.1

Malicious code in ng-search-api (npm)

T1195.002 · Compromise Software Supply ChainT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

ng-search-api@99.9.1 is a dependency-confusion stub (empty index.js, 351 bytes, version 99.9.1, no description). Its sole dependency "ltidisafe" is pinned to a remote tarball at hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3.0.5.tgz, so npm install fetches a payload from attacker-controlled storage. The install fails on a malformed tarball before execution, but the package has no legitimate purpose beyond pulling code from that external host.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 08:12 AM
analyzed
Jun 11, 2026, 08:13 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.