notifications-broadcast@99.9.1
Malicious code in notifications-broadcast (npm)
Analysis
Dependency-confusion attack: notifications-broadcast@99.9.1 is an empty package (index.js exports an empty object) that declares a single dependency hosted on an external URL rather than the npm registry. On install, npm fetches the dependency tarball from hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]3[.]4[.]tgz — an attacker-controlled Google Cloud Storage bucket that can serve arbitrary malicious code. The high version (99.9.1) is a dependency-confusion outranking tactic designed to be installed in place of a legitimate internal package with the same name.
- analyzed by
- Leitwacht
- first seen
- Jul 12, 2026, 06:31 AM
- analyzed
- Jul 12, 2026, 06:31 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.