LWA-2026-6382 MAL-2026-6989 ↗ confirmed malware

ag-charts-test@99.9.1

Malicious code in ag-charts-test (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Combosquat of the legitimate ag-charts package (AG Grid charting library). The package ships no functional code — index.js is a stub exporting an empty object. Its sole purpose is to declare an external dependency on "ltidisafe" fetched from a Google Cloud Storage bucket (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]1[.]9[.]tgz), which is loaded and installed as a regular npm dependency at install time. This allows the attacker to serve arbitrary malicious code from the external tarball under the guise of a dependency. The version 99.9.1 is a dependency-confusion tactic to outrank legitimate versions.

analyzed by
Leitwacht
first seen
Jul 7, 2026, 08:41 AM
analyzed
Jul 7, 2026, 08:42 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.