wac-atl-context@99.9.1
Malicious code in wac-atl-context (npm)
Analysis
Package wac-atl-context@99.9.1 is a stub with no legitimate functionality. It declares a single dependency fetched from a Google Cloud Storage CDN (ltidi[.]storage[.]googleapis[.]com) rather than the npm registry. The remote tarball hosted at that URL can be swapped at any time to serve arbitrary code. The package has no description, no repository, no README, and its index.js only prints an unrelated string. The dependency is downloaded into node_modules at install time and can be loaded by any code that requires it. This setup provides a supply-chain vector: the attacker controls the remote tarball and can replace it with a malicious payload, or publish a follow-up version that activates it.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 11:13 PM
- analyzed
- Jun 15, 2026, 11:14 PM
Related advisories
- transform-es2015-classes@6.25.1
- transform-es3-member-expression-literals@6.24.0
- toast-react-slider@1.0.0
- redirect-azlazy@1.0.0
- oit-lib-oracle-util@45.0.0
- no-date-parsing@2.2.0
- firefly-utilities-helper@99.9.1
- optional-cpu-features@1.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.