LWA-2026-4850 MAL-2026-6670 ↗ confirmed malware

rc-icon@99.9.1

Malicious code in rc-icon (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Package rc-icon@99.9.1 is a dependency-confusion vehicle. Its only purpose is to pull an unvetted external dependency into the installer's build pipeline: it declares a dependency on "ltidisafe" hosted at an external Google Cloud Storage URL rather than from the npm registry. The package body is a 26-byte stub (console.log("ltidifromh1")) with no functional value, and the version 99.9.1 is set absurdly high to hijack semver resolution over any legitimate rc-icon version. Installing this package causes the installer's npm to fetch and execute code from an attacker-controlled GCS bucket, enabling arbitrary code execution in the build environment — a supply-chain initial-access attack.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 08:08 PM
analyzed
Jun 12, 2026, 08:09 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.