LWA-2026-6038 MAL-2026-6546 ↗ confirmed malware

ryan-pdf-js@99.9.1

Malicious code in ryan-pdf-js (npm)

T1195 · Supply Chain CompromiseT1195.001 · Compromise Software Dependencies and Development Tools

Analysis

Package ryan-pdf-js@99.9.1 is a dependency-confusion attack. The package itself contains only an empty code stub (module.exports = {}), but its single dependency resolves to an external tarball hosted at hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]1[.]1[.]tgz. The high version (99.9.1) and impersonating name ("ryan-pdf-js", suggestive of a corporate/internal package) ensure it wins over any legitimate internal package during dependency resolution. The external tarball is fetched and extracted at install time; if the hosted tarball contains lifecycle scripts (preinstall/postinstall), those scripts execute on the installer's machine during npm install.

analyzed by
Leitwacht
first seen
Jun 27, 2026, 11:06 AM
analyzed
Jun 27, 2026, 11:07 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.