@spending-behavior-ui/cashflow-widget@99.9.1
Malicious code in @spending-behavior-ui/cashflow-widget (npm)
Analysis
Dependency-confusion packages published at version 99.9.1 with scoped names mimicking internal UI component namespaces (@spending-behavior-ui/cashflow-widget, @spending-behavior-ui/widget-insights, @sw-commons-components/message-upsell, process-status-widget). Each package is an empty stub (module.exports = {}) with no repository, no description, and no lifecycle hooks, but declares a single dependency fetched from a non-registry URL at ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-*.tgz. The off-registry tarball is served from Google Cloud Storage and is fetched automatically at install time, allowing the attacker to serve arbitrary payloads without further publishes.
- analyzed by
- Leitwacht
- first seen
- Jul 14, 2026, 03:17 AM
- analyzed
- Jul 14, 2026, 04:09 AM
Related advisories
- @spending-behavior-ui/widget-insights@99.9.1
- @finance-ui/finance-view@99.9.1
- elsisi-cli@9.9.9
- chai-as-auth@2.3.5
- polymarket-bot-logger@1.0.1
- @sqlite-panel/createsql@1.0.0
- type-swap@3.1.3
- test_adminet@99.9.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.