metrics-ui@99.9.1
Malicious code in metrics-ui (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
metrics-ui@99.9.1 is a dependency-confusion package containing only a 35-byte stub (module.exports = {}). Its sole dependency is an external tarball hosted at ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3.4.4.tgz, which bypasses npm registry scanning. When installed, npm fetches this attacker-controlled tarball, allowing arbitrary code execution on the installer's system. The high version number (99.9.1) is designed to win version resolution against any legitimate package with a similar name.
- analyzed by
- Leitwacht
- first seen
- Jul 15, 2026, 05:04 PM
- analyzed
- Jul 15, 2026, 05:05 PM
Related advisories
- react-hook-scripts@5.4.2
- code-formatter-setup@1.0.0
- ai-pro-sdk@2.0.3
- react-hook-doms@5.3.1
- assertion-utils-js@2.4.3
- @risaoffc/baileys@8.0.3
- chai-as-hardened@7.0.9
- @asyncapi/specs@6.11.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.