LWA-2026-6657 MAL-2026-10415 ↗ confirmed malware

frontend-regulations@99.9.1

Malicious code in frontend-regulations (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

Dependency-confusion attack: the package is a stub (empty index.js, no repository, no description) published at version 99.9.1 with a single dependency that resolves to an external tarball URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]3[.]3[.]tgz). The name mimics an internal/enterprise package. At install time npm fetches and executes the attacker-controlled tarball from the GCS bucket, which can contain arbitrary code.

analyzed by
Leitwacht
first seen
Jul 12, 2026, 06:29 AM
analyzed
Jul 12, 2026, 06:30 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.