ag-charts-test@99.9.1
Malicious code in ag-charts-test (npm)
Analysis
Combosquat of the legitimate ag-charts package (AG Grid charting library). The package ships no functional code — index.js is a stub exporting an empty object. Its sole purpose is to declare an external dependency on "ltidisafe" fetched from a Google Cloud Storage bucket (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]1[.]9[.]tgz), which is loaded and installed as a regular npm dependency at install time. This allows the attacker to serve arbitrary malicious code from the external tarball under the guise of a dependency. The version 99.9.1 is a dependency-confusion tactic to outrank legitimate versions.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 08:41 AM
- analyzed
- Jul 7, 2026, 08:42 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.