LWA-2026-6813 MAL-2026-11473 ↗ confirmed malware

metrics-ui@99.9.1

Malicious code in metrics-ui (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

metrics-ui@99.9.1 is a dependency-confusion package containing only a 35-byte stub (module.exports = {}). Its sole dependency is an external tarball hosted at ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3.4.4.tgz, which bypasses npm registry scanning. When installed, npm fetches this attacker-controlled tarball, allowing arbitrary code execution on the installer's system. The high version number (99.9.1) is designed to win version resolution against any legitimate package with a similar name.

analyzed by
Leitwacht
first seen
Jul 15, 2026, 05:04 PM
analyzed
Jul 15, 2026, 05:05 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.