LWA-2026-5463 MAL-2026-6671 ↗ confirmed malware

wac-atl-context@99.9.1

Malicious code in wac-atl-context (npm)

T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise

Analysis

Package wac-atl-context@99.9.1 is a stub with no legitimate functionality. It declares a single dependency fetched from a Google Cloud Storage CDN (ltidi[.]storage[.]googleapis[.]com) rather than the npm registry. The remote tarball hosted at that URL can be swapped at any time to serve arbitrary code. The package has no description, no repository, no README, and its index.js only prints an unrelated string. The dependency is downloaded into node_modules at install time and can be loaded by any code that requires it. This setup provides a supply-chain vector: the attacker controls the remote tarball and can replace it with a malicious payload, or publish a follow-up version that activates it.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 11:13 PM
analyzed
Jun 15, 2026, 11:14 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.