LWA-2026-6739 MAL-2026-11452 ↗ confirmed malware

@sw-commons-components/message-upsell@99.9.1

Malicious code in @sw-commons-components/message-upsell (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Dependency-confusion packages published at version 99.9.1 with scoped names mimicking internal UI component namespaces (@spending-behavior-ui/cashflow-widget, @spending-behavior-ui/widget-insights, @sw-commons-components/message-upsell, process-status-widget). Each package is an empty stub (module.exports = {}) with no repository, no description, and no lifecycle hooks, but declares a single dependency fetched from a non-registry URL at ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-*.tgz. The off-registry tarball is served from Google Cloud Storage and is fetched automatically at install time, allowing the attacker to serve arbitrary payloads without further publishes.

analyzed by
Leitwacht
first seen
Jul 14, 2026, 03:18 AM
analyzed
Jul 14, 2026, 04:09 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.