sso-users-detection@99.9.1
Malicious code in sso-users-detection (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
Dependency-confusion package published at version 99.9.1 with no functional code (empty module.exports). The package declares a single dependency, ltidisafe, fetched from a non-registry HTTPS URL (ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3.3.1.tgz). When installed, npm downloads and extracts this externally-hosted tarball, which may contain arbitrary code. The high version number is characteristic of dependency-confusion attacks targeting internal/private package names.
- analyzed by
- Leitwacht
- first seen
- Jul 12, 2026, 06:27 AM
- analyzed
- Jul 12, 2026, 06:27 AM
Related advisories
- tinyparrot@0.4.1
- svg-fetcher@2.4.1
- cookie-sign@2.3.5
- react-hot-svg@1.1.5
- polymarket-kelly-math-stake@3.6.2
- supertokens-web@1.16.0
- chai-as-doc@2.3.5
- llama-tokenizer@1.2.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.