@sw-commons-components/message-upsell@99.9.1
Malicious code in @sw-commons-components/message-upsell (npm)
Analysis
Dependency-confusion packages published at version 99.9.1 with scoped names mimicking internal UI component namespaces (@spending-behavior-ui/cashflow-widget, @spending-behavior-ui/widget-insights, @sw-commons-components/message-upsell, process-status-widget). Each package is an empty stub (module.exports = {}) with no repository, no description, and no lifecycle hooks, but declares a single dependency fetched from a non-registry URL at ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-*.tgz. The off-registry tarball is served from Google Cloud Storage and is fetched automatically at install time, allowing the attacker to serve arbitrary payloads without further publishes.
- analyzed by
- Leitwacht
- first seen
- Jul 14, 2026, 03:18 AM
- analyzed
- Jul 14, 2026, 04:09 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.