LWA-2026-6702 MAL-2026-11449 ↗ confirmed malware

@sof-assistant-fe-lib/vertical-faqs@99.9.1

Malicious code in @sof-assistant-fe-lib/vertical-faqs (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Dependency-confusion attack. The package @sof-assistant-fe-lib/vertical-faqs@99.9.1 is an empty stub (module.exports = {}) that declares a single dependency fetched from an external URL: hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]2[.]9[.]tgz. When installed, npm downloads and extracts this remote tarball, which can execute arbitrary code. The high version (99.9.1) and scoped name are designed to win dependency resolution against any legitimate internal package with the same name. The package has no repository, no description, and no functional code — its sole purpose is to pull in the remote payload.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 12:53 PM
analyzed
Jul 13, 2026, 12:54 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.