@mplay-frontend-ui/link@99.9.1
Malicious code in @mplay-frontend-ui/link (npm)
Analysis
Dependency-confusion attack package. @mplay-frontend-ui/link@99.9.1 is an empty stub (module.exports = {}) published at a sentinel version 99.9.1 under a scoped name that mimics an internal/private UI library. It declares a single dependency, ltidisafe, fetched from an external Google Cloud Storage URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]2[.]6[.]tgz). When installed, npm resolves and downloads this external tarball, executing whatever payload it contains. The high version ensures the package takes precedence over any legitimate internal package with the same scoped name.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 11:48 AM
- analyzed
- Jul 13, 2026, 11:48 AM
Related advisories
- markable-table@3.1.0
- awesome-terminal@1.0.3
- type-context@3.2.7
- terminal-mascot@3.5.2
- decimal-format-core@3.5.4
- dilxztech@1.0.0
- chai-as-precision@7.0.6
- gptcore@4.0.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.