ring-device-settings-library@45.0.0
Malicious code in ring-device-settings-library (npm)
Analysis
ring-device-settings-library@45.0.0 is a dependency-confusion malware shim. The package declares a dependency on itself resolved from the external attacker-controlled host hxxps://repo[.]securityctrl[.]com/ring-device-settings-library. When installed, npm fetches the dependency tarball from that URL instead of the registry, pulling in malicious code. The package's own source is a 79-byte placeholder with no real functionality — the payload is served externally at the time of install. The external host repo[.]securityctrl[.]com serves the malicious dependency.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 07:03 AM
- analyzed
- Jun 13, 2026, 07:05 AM
Related advisories
- request-js-validator@1.0.2
- macos-ci-utils@1.0.1
- redirect-azlazy@1.0.0
- redeem-onchain-sdk@1.0.1
- react-svg-chunk@1.1.0
- react-schedule-it@4.0.0
- warp-dependency@1.0.0
- @wacrot/infra-data-kit@2.1.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.