@higherlogic/ocfe@99.9.1
Malicious code in @higherlogic/ocfe (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Dependency-confusion package @higherlogic/ocfe at version 99.9.1. The package declares a dependency on a remote tarball hosted at ltidi[.]storage[.]googleapis[.]com (ltidisafe-3.1.5.tgz), which is fetched and installed at runtime. The package has no repository, no description, and a minimal index.js stub, consistent with a remote-code-execution dropper pattern.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 09:52 AM
- analyzed
- Jul 7, 2026, 01:12 PM
Related advisories
- motion-pull@2.3.5
- paperclip-host-utils@1.0.0
- chai-smart@2.3.5
- express-mongo-limit@2.0.1
- tailwind-animate-v4@2.1.0
- higherlogic-ocfe@99.9.1
- crypto-promiser@1.0.1
- events-alias@15.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.