@sof-assistant-fe-lib/vertical-faqs@99.9.1
Malicious code in @sof-assistant-fe-lib/vertical-faqs (npm)
Analysis
Dependency-confusion attack. The package @sof-assistant-fe-lib/vertical-faqs@99.9.1 is an empty stub (module.exports = {}) that declares a single dependency fetched from an external URL: hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]2[.]9[.]tgz. When installed, npm downloads and extracts this remote tarball, which can execute arbitrary code. The high version (99.9.1) and scoped name are designed to win dependency resolution against any legitimate internal package with the same name. The package has no repository, no description, and no functional code — its sole purpose is to pull in the remote payload.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 12:53 PM
- analyzed
- Jul 13, 2026, 12:54 PM
Related advisories
- font-hub@1.5.2
- remarkable-table@2.4.11
- react-markable-table@2.4.10
- markdown-editable-table@2.4.2
- router-processor@1.5.2
- node-procmetrics@1.0.6
- @fuji-web-components/maps@99.9.1
- awesome-terminal@1.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.