polylabel-web-lib@99.9.1
Malicious code in polylabel-web-lib (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
polylabel-web-lib is a combosquat of the legitimate polylabel package. The package contains no functional code (index.js exports an empty object). Its sole dependency, ltidisafe, is declared via a direct HTTPS URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]2[.]2[.]tgz) rather than the npm registry. Installing this package causes npm to download and install the external tarball, which can deliver arbitrary code at install time. The package has no repository, no description, and no stated purpose.
- analyzed by
- Leitwacht
- first seen
- Jul 12, 2026, 03:53 PM
- analyzed
- Jul 12, 2026, 03:53 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.