LWA-2026-6818 MAL-2026-11442 ↗ confirmed malware

@mp-op-ss-front-lib/tracks@99.9.1

Malicious code in @mp-op-ss-front-lib/tracks (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Dependency-confusion stub at version 99.9.1 on a scoped name. The package is an empty module (module.exports = {}) with no description, repository, or lifecycle scripts. Its only purpose is declaring a dependency on `ltidisafe` from the external URL `hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]4[.]3[.]tgz` — a Google Cloud Storage bucket, not the npm registry. When installed, npm fetches and installs the attacker-controlled tarball from that URL.

analyzed by
Leitwacht
first seen
Jul 15, 2026, 05:16 PM
analyzed
Jul 15, 2026, 05:17 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.