ryan-pdf-js@99.9.1
Malicious code in ryan-pdf-js (npm)
Analysis
Package ryan-pdf-js@99.9.1 is a dependency-confusion attack. The package itself contains only an empty code stub (module.exports = {}), but its single dependency resolves to an external tarball hosted at hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]1[.]1[.]tgz. The high version (99.9.1) and impersonating name ("ryan-pdf-js", suggestive of a corporate/internal package) ensure it wins over any legitimate internal package during dependency resolution. The external tarball is fetched and extracted at install time; if the hosted tarball contains lifecycle scripts (preinstall/postinstall), those scripts execute on the installer's machine during npm install.
- analyzed by
- Leitwacht
- first seen
- Jun 27, 2026, 11:06 AM
- analyzed
- Jun 27, 2026, 11:07 AM
Related advisories
- @paoletti/viem@2.53.1
- uphold-sdk-javascript-extensions@99.9.10
- chai-as-assured@7.1.2
- ollama-helpers@0.2.1
- aikaf668897@1.0.3
- wm-idp-sdk@1.2.0
- wac-atl-context@99.9.1
- transform-es2015-classes@6.25.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.