tracking-service-config@90.0.0
Malicious code in tracking-service-config (npm)
Analysis
tracking-service-config@90.0.0 defines a dependency ("base-package") pointing to an attacker-controlled external HTTP URL (hxxp://npm[.]ezequielpuig[.]space/) rather than the npm registry. When this package is installed, npm resolves the dependency from that external URL, which can serve arbitrary malicious code to the victim's build pipeline. The package ships no actual source code (empty index.js) — its sole function is as a dependency-confusion vector to inject attacker-controlled packages into the install chain via the non-registry dependency specifier. Version 90.0.0 is a version-squat intended to be preferred over legitimate versions.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 05:33 AM
- analyzed
- Jun 15, 2026, 05:34 AM
Related advisories
- totally-legit-web-pack@1.2.5
- hemi-supply-cron@999.0.0
- thienc-cdn@1.0.0
- third-sender@1.0.0
- ve-hemi-rewards@999.0.0
- token-prices-cron@999.0.0
- vaults-monitor-cron@999.0.0
- hemi-earn-actions@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.