LWA-2026-6735 MAL-2026-11437 ↗ confirmed malware

@finance-ui/snackbar-ifpe@99.9.1

Malicious code in @finance-ui/snackbar-ifpe (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

@finance-ui/snackbar-ifpe@99.9.1 is a dependency-confusion stub with no functional code. Its package.json declares a dependency on a tarball hosted at ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3.3.5.tgz — a non-registry URL that delivers the actual payload on install. The package uses version 99.9.1 to out-rank any legitimate internal package with a similar name. The sole file (index.js) is empty (module.exports = {}); the package has no repository, no description, and no README. Installing this package causes npm to fetch and execute the remote tarball from Google Storage CDN.

analyzed by
Leitwacht
first seen
Jul 14, 2026, 03:02 AM
analyzed
Jul 14, 2026, 03:20 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.