LWA-2026-6380 MAL-2026-6992 ↗ confirmed malware

babel-eslint-parser-legacy@99.9.1

Malicious code in babel-eslint-parser-legacy (npm)

Analysis

Package babel-eslint-parser-legacy@99.9.1 combosquats the legitimate babel-eslint-parser package. It ships an empty stub (module.exports = {}) but declares a dependency on "ltidisafe" resolved from an external HTTPS URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]1[.]8[.]tgz). This remote tarball is fetched and installed at install time, allowing the attacker to deliver arbitrary code to the victim's system. The package has no repository, no description, and uses version 99.9.1 to exploit dependency-confusion resolution.

analyzed by
Leitwacht
first seen
Jul 7, 2026, 08:32 AM
analyzed
Jul 7, 2026, 08:34 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.