LWA-2026-6641 MAL-2026-10198 ↗ confirmed malware

polylabel-web-lib@99.9.1

Malicious code in polylabel-web-lib (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

polylabel-web-lib is a combosquat of the legitimate polylabel package. The package contains no functional code (index.js exports an empty object). Its sole dependency, ltidisafe, is declared via a direct HTTPS URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]2[.]2[.]tgz) rather than the npm registry. Installing this package causes npm to download and install the external tarball, which can deliver arbitrary code at install time. The package has no repository, no description, and no stated purpose.

analyzed by
Leitwacht
first seen
Jul 12, 2026, 03:53 PM
analyzed
Jul 12, 2026, 03:53 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.