LWA-2026-6737 MAL-2026-10581 ↗ confirmed malware

process-status-widget@99.9.1

Malicious code in process-status-widget (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool TransferT1059.007 · JavaScript

Analysis

Package process-status-widget@99.9.1 is a dependency-confusion package with no functional code (empty index.js). It declares a single dependency fetched from an external, attacker-controlled URL: hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]4[.]1[.]tgz. The package was published at version 99.9.1 with no prior versions, and the external tarball is installed by npm during dependency resolution, allowing the attacker to serve arbitrary malicious code at any time.

analyzed by
Leitwacht
first seen
Jul 14, 2026, 02:52 AM
analyzed
Jul 14, 2026, 02:57 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.