@genie-auth/config@99.9.1
Malicious code in @genie-auth/config (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
@genie-auth/config@99.9.1 is a dependency-confusion stub (version 99.9.1, 355 bytes) whose 35-byte index.js exports an empty object, but whose sole dependency "ltidisafe" is pinned to a remote tarball at hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3.0.7.tgz. On install npm attempts to fetch that tarball, pulling the real payload from attacker-controlled storage. The stub has no lifecycle hooks; the attack is delivered through the remote dependency.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 05:57 PM
- analyzed
- Jun 11, 2026, 05:58 PM
Related advisories
- vite-tsconfig@1.1.2
- chalk-plus-ts@1.0.3
- bubblestring@1.1.4
- npm-doc-dev@1.0.9
- chalk-plus-js@7.0.4
- noon-contracts@1.0.0
- express-initial@12.1.7
- sn-internal-testjgsakjdkjadkjahsdkjad@2.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.