portway@99.9.1
Malicious code in portway (npm)
Analysis
portway@99.9.1 is a dependency-confusion package with no functional code. It declares a dependency on "ltidisafe" fetched from an external Google Cloud Storage URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]3[.]2[.]tgz). The attacker controls the tarball at that URL, which can execute arbitrary code during installation via lifecycle hooks in the dependency. The package has no repository, no description, and exports an empty object.
- analyzed by
- Leitwacht
- first seen
- Jul 12, 2026, 06:28 AM
- analyzed
- Jul 12, 2026, 06:28 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.