po-ops-local-dev@99.9.1
Malicious code in po-ops-local-dev (npm)
Analysis
Dependency-confusion attack. The package po-ops-local-dev@99.9.1 is an empty stub (module.exports = {}) that declares a single dependency, ltidisafe, fetched from an attacker-controlled Google Cloud Storage URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-2[.]9[.]2[.]tgz). The high version 99.9.1 is designed to out-version any legitimate internal package with a similar name. When installed, npm downloads and installs the remote ltidisafe tarball from the attacker's bucket, which can contain lifecycle hooks that execute arbitrary code on the victim's machine. The package has no repository, no description, and no README.
- analyzed by
- Leitwacht
- first seen
- Jul 8, 2026, 05:41 PM
- analyzed
- Jul 8, 2026, 05:43 PM
Related advisories
- webrix-docs1@10.2.11
- lusha-iam-widgets@1.5.2
- driftpin@1.0.0
- ryan-pdf-js@99.9.1
- chai-as-assured@7.1.2
- ollama-helpers@0.2.1
- aikaf668897@1.0.3
- wm-idp-sdk@1.2.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.