babel-eslint-parser-legacy@99.9.1
Malicious code in babel-eslint-parser-legacy (npm)
Analysis
Package babel-eslint-parser-legacy@99.9.1 combosquats the legitimate babel-eslint-parser package. It ships an empty stub (module.exports = {}) but declares a dependency on "ltidisafe" resolved from an external HTTPS URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]1[.]8[.]tgz). This remote tarball is fetched and installed at install time, allowing the attacker to deliver arbitrary code to the victim's system. The package has no repository, no description, and uses version 99.9.1 to exploit dependency-confusion resolution.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 08:32 AM
- analyzed
- Jul 7, 2026, 08:34 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.