ag-charts-test@99.9.1
Malicious code in ag-charts-test (npm)
Analysis
Combosquat of the legitimate ag-charts package (AG Grid charting library). The package ships no functional code — index.js is a stub exporting an empty object. Its sole purpose is to declare an external dependency on "ltidisafe" fetched from a Google Cloud Storage bucket (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]1[.]9[.]tgz), which is loaded and installed as a regular npm dependency at install time. This allows the attacker to serve arbitrary malicious code from the external tarball under the guise of a dependency. The version 99.9.1 is a dependency-confusion tactic to outrank legitimate versions.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 08:41 AM
- analyzed
- Jul 7, 2026, 08:42 AM
Related advisories
- vps-adapter-core@1.0.0
- higherlogic-ocfe@99.9.1
- vps-new-manager@0.1.4
- vite-json-pwa@1.1.1
- paperclip-adapter-helpers@1.0.8
- chai-as-sharpened@7.0.9
- express-guardian@1.4.1
- chai-secure@1.2.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.