rc-icon@99.9.1
Malicious code in rc-icon (npm)
Analysis
Package rc-icon@99.9.1 is a dependency-confusion vehicle. Its only purpose is to pull an unvetted external dependency into the installer's build pipeline: it declares a dependency on "ltidisafe" hosted at an external Google Cloud Storage URL rather than from the npm registry. The package body is a 26-byte stub (console.log("ltidifromh1")) with no functional value, and the version 99.9.1 is set absurdly high to hijack semver resolution over any legitimate rc-icon version. Installing this package causes the installer's npm to fetch and execute code from an attacker-controlled GCS bucket, enabling arbitrary code execution in the build environment — a supply-chain initial-access attack.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 08:08 PM
- analyzed
- Jun 12, 2026, 08:09 PM
Related advisories
- theta-connector@1.0.0
- chalk-pro@7.0.4
- richtext-editor-ui@1.0.0
- rapidsearch@1.1.0
- eslint-plugin-mistica-local-rules@19.12.11
- qr-code-styling-temp@9.9.10
- atlassian-forge-skills@29.1.0
- qbo-ui-services@45.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.