@one-chat/react@99.9.1
Malicious code in @one-chat/react (npm)
Analysis
Seven dependency-confusion packages published at version 99.9.1, each an empty stub (no code, no lifecycle hooks) that declares a single dependency on a remote tarball hosted at ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-*.tgz. The scoped names (@meli-testing/jest-react, @nordic-dev/linting-tools, @fuji-web-components/maps, @mplay-core-lib/utilities, @mplay-frontend-ui/link, @global-theme/context, @one-chat/react) mimic internal/private organization packages, and the sentinel version 99.9.1 ensures they win dependency resolution. When installed, npm fetches and extracts the remote ltidisafe tarball from the Google Cloud Storage bucket, which is the actual payload. The remote tarball URLs are: hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]2[.]4[.]tgz, hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]2[.]7[.]tgz, hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]2[.]3[.]tgz, and similar version variants across the packages.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 11:48 AM
- analyzed
- Jul 13, 2026, 11:49 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.