@finance-ui/snackbar-ifpe@99.9.1
Malicious code in @finance-ui/snackbar-ifpe (npm)
Analysis
@finance-ui/snackbar-ifpe@99.9.1 is a dependency-confusion stub with no functional code. Its package.json declares a dependency on a tarball hosted at ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3.3.5.tgz — a non-registry URL that delivers the actual payload on install. The package uses version 99.9.1 to out-rank any legitimate internal package with a similar name. The sole file (index.js) is empty (module.exports = {}); the package has no repository, no description, and no README. Installing this package causes npm to fetch and execute the remote tarball from Google Storage CDN.
- analyzed by
- Leitwacht
- first seen
- Jul 14, 2026, 03:02 AM
- analyzed
- Jul 14, 2026, 03:20 AM
Related advisories
browse all confirmed advisories →Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.