LWA-2026-6676 MAL-2026-11444 ↗ confirmed malware

@mplay-frontend-ui/link@99.9.1

Malicious code in @mplay-frontend-ui/link (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Dependency-confusion attack package. @mplay-frontend-ui/link@99.9.1 is an empty stub (module.exports = {}) published at a sentinel version 99.9.1 under a scoped name that mimics an internal/private UI library. It declares a single dependency, ltidisafe, fetched from an external Google Cloud Storage URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]2[.]6[.]tgz). When installed, npm resolves and downloads this external tarball, executing whatever payload it contains. The high version ensures the package takes precedence over any legitimate internal package with the same scoped name.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 11:48 AM
analyzed
Jul 13, 2026, 11:48 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.