LWA-2026-6465 MAL-2026-5159 ↗ confirmed malware

po-ops-local-dev@99.9.1

Malicious code in po-ops-local-dev (npm)

T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise

Analysis

Dependency-confusion attack. The package po-ops-local-dev@99.9.1 is an empty stub (module.exports = {}) that declares a single dependency, ltidisafe, fetched from an attacker-controlled Google Cloud Storage URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-2[.]9[.]2[.]tgz). The high version 99.9.1 is designed to out-version any legitimate internal package with a similar name. When installed, npm downloads and installs the remote ltidisafe tarball from the attacker's bucket, which can contain lifecycle hooks that execute arbitrary code on the victim's machine. The package has no repository, no description, and no README.

analyzed by
Leitwacht
first seen
Jul 8, 2026, 05:41 PM
analyzed
Jul 8, 2026, 05:43 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.