LWA-2026-6738 MAL-2026-11451 ↗ confirmed malware

@spending-behavior-ui/widget-insights@99.9.1

Malicious code in @spending-behavior-ui/widget-insights (npm)

Analysis

Dependency-confusion packages published at version 99.9.1 with scoped names mimicking internal UI component namespaces (@spending-behavior-ui/cashflow-widget, @spending-behavior-ui/widget-insights, @sw-commons-components/message-upsell, process-status-widget). Each package is an empty stub (module.exports = {}) with no repository, no description, and no lifecycle hooks, but declares a single dependency fetched from a non-registry URL at ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-*.tgz. The off-registry tarball is served from Google Cloud Storage and is fetched automatically at install time, allowing the attacker to serve arbitrary payloads without further publishes.

analyzed by
Leitwacht
first seen
Jul 14, 2026, 03:17 AM
analyzed
Jul 14, 2026, 04:09 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.