home-sections-web-ui@99.9.9
Malicious code in home-sections-web-ui (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Dependency-confusion package at version 99.9.9 that declares a dependency "ltidisafe" pointing to an external tarball hosted at hxxps://storage[.]googleapis[.]com/lscunpentest/pack_ux_foundry[.]tgz. The package itself is a minimal stub (397 bytes, index.js contains only a console.log). The actual payload is delivered from the external GCS-hosted tarball when npm install resolves the dependency. The package has no repository, no lifecycle hooks, and its description is a nonsensical string ("lspodcc").
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 10:20 AM
- analyzed
- Jul 13, 2026, 10:21 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.