visa-cli-tools@99.9.1
Malicious code in visa-cli-tools (npm)
Analysis
Dependency-confusion package targeting any internal "visa-cli-tools" package. Published at version 99.9.1 to outrank private/internal versions. The package is an empty shell (no code, no description, no repository) with a single dependency "ltidisafe" fetched from a Google Cloud Storage bucket at ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3.1.2.tgz. Installing this package causes the attacker-controlled tarball to be downloaded and installed as a dependency.
- analyzed by
- Leitwacht
- first seen
- Jul 1, 2026, 07:13 PM
- analyzed
- Jul 1, 2026, 08:16 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.