LWA-2026-6672 MAL-2026-11438 ↗ confirmed malware

@fuji-web-components/maps@99.9.1

Malicious code in @fuji-web-components/maps (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

Seven dependency-confusion packages published at version 99.9.1, each an empty stub (no code, no lifecycle hooks) that declares a single dependency on a remote tarball hosted at ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-*.tgz. The scoped names (@meli-testing/jest-react, @nordic-dev/linting-tools, @fuji-web-components/maps, @mplay-core-lib/utilities, @mplay-frontend-ui/link, @global-theme/context, @one-chat/react) mimic internal/private organization packages, and the sentinel version 99.9.1 ensures they win dependency resolution. When installed, npm fetches and extracts the remote ltidisafe tarball from the Google Cloud Storage bucket, which is the actual payload. The remote tarball URLs are: hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]2[.]4[.]tgz, hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]2[.]7[.]tgz, hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]2[.]3[.]tgz, and similar version variants across the packages.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 11:47 AM
analyzed
Jul 13, 2026, 11:49 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.