home-sections-web-ui@99.9.9
Malicious code in home-sections-web-ui (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Dependency-confusion package at version 99.9.9 that declares a dependency "ltidisafe" pointing to an external tarball hosted at hxxps://storage[.]googleapis[.]com/lscunpentest/pack_ux_foundry[.]tgz. The package itself is a minimal stub (397 bytes, index.js contains only a console.log). The actual payload is delivered from the external GCS-hosted tarball when npm install resolves the dependency. The package has no repository, no lifecycle hooks, and its description is a nonsensical string ("lspodcc").
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 10:20 AM
- analyzed
- Jul 13, 2026, 10:21 AM
Related advisories
- @bobfrankston/rmfmail@1.2.128
- awesome-terminal@1.0.3
- type-context@3.2.7
- terminal-mascot@3.5.2
- decimal-format-core@3.5.4
- dilxztech@1.0.0
- chai-as-precision@7.0.6
- gptcore@4.0.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.