LWA-2026-6656 MAL-2026-10422 ↗ confirmed malware

sso-users-detection@99.9.1

Malicious code in sso-users-detection (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

Dependency-confusion package published at version 99.9.1 with no functional code (empty module.exports). The package declares a single dependency, ltidisafe, fetched from a non-registry HTTPS URL (ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3.3.1.tgz). When installed, npm downloads and extracts this externally-hosted tarball, which may contain arbitrary code. The high version number is characteristic of dependency-confusion attacks targeting internal/private package names.

analyzed by
Leitwacht
first seen
Jul 12, 2026, 06:27 AM
analyzed
Jul 12, 2026, 06:27 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.