LWA-2026-6632 MAL-2026-10419 ↗ confirmed malware

notifications-broadcast@99.9.1

Malicious code in notifications-broadcast (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Dependency-confusion attack: notifications-broadcast@99.9.1 is an empty package (index.js exports an empty object) that declares a single dependency hosted on an external URL rather than the npm registry. On install, npm fetches the dependency tarball from hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]3[.]4[.]tgz — an attacker-controlled Google Cloud Storage bucket that can serve arbitrary malicious code. The high version (99.9.1) is a dependency-confusion outranking tactic designed to be installed in place of a legitimate internal package with the same name.

analyzed by
Leitwacht
first seen
Jul 12, 2026, 06:31 AM
analyzed
Jul 12, 2026, 06:31 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.