oem-agentic-shared@99.9.1
Malicious code in oem-agentic-shared (npm)
Analysis
This package is an empty placeholder whose only purpose is to act as a dependency-confusion vehicle. It publishes an inflated version (99.9.1) of an internal-sounding name so that it wins version resolution over a legitimate same-named internal package. Its package.json declares a single dependency that is fetched not from the npm registry but from an external HTTPS tarball hosted on Google Cloud Storage (the URL path is named after dependency confusion). On install, npm downloads and unpacks that external, attacker-controlled tarball, delivering the actual payload while the published package itself contains only an empty module.
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 01:34 AM
- analyzed
- Jun 18, 2026, 01:52 AM
Related advisories
- chai-plugin-kit@5.8.1
- proto-bin@2.3.3
- easyllmai@3.0.1
- ssr-auth-sync@1.6.16
- chai-plugin-helper@1.7.3
- nat-ulid@3.0.2
- @caspianph/storyteller@1.1.13
- xeiko-cdn@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.