LWA-2026-4374 MAL-2026-10141 ↗ confirmed malware

@genie-auth/config@99.9.1

Malicious code in @genie-auth/config (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

@genie-auth/config@99.9.1 is a dependency-confusion stub (version 99.9.1, 355 bytes) whose 35-byte index.js exports an empty object, but whose sole dependency "ltidisafe" is pinned to a remote tarball at hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3.0.7.tgz. On install npm attempts to fetch that tarball, pulling the real payload from attacker-controlled storage. The stub has no lifecycle hooks; the attack is delivered through the remote dependency.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 05:57 PM
analyzed
Jun 11, 2026, 05:58 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.