frontend-regulations@99.9.1
Malicious code in frontend-regulations (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
Dependency-confusion attack: the package is a stub (empty index.js, no repository, no description) published at version 99.9.1 with a single dependency that resolves to an external tarball URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]3[.]3[.]tgz). The name mimics an internal/enterprise package. At install time npm fetches and executes the attacker-controlled tarball from the GCS bucket, which can contain arbitrary code.
- analyzed by
- Leitwacht
- first seen
- Jul 12, 2026, 06:29 AM
- analyzed
- Jul 12, 2026, 06:30 AM
Related advisories
- sso-users-detection@99.9.1
- tinyparrot@0.4.1
- svg-fetcher@2.4.1
- cookie-sign@2.3.5
- react-hot-svg@1.1.5
- polymarket-kelly-math-stake@3.6.2
- supertokens-web@1.16.0
- chai-as-doc@2.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.