requestor-util@99.9.1
Malicious code in requestor-util (npm)
Analysis
Dependency-confusion package requestor-util@99.9.1 is a hollow module (empty index.js, no description, no repository) that declares a single dependency fetched from an attacker-controlled Google Cloud Storage URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]4[.]6[.]tgz). At install time, npm downloads and extracts this remote tarball, enabling arbitrary code execution on the installer's machine. The high version number (99.9.1) and empty package body are characteristic of a dependency-confusion attack targeting internal/private package resolution.
- analyzed by
- Leitwacht
- first seen
- Jul 21, 2026, 04:29 AM
- analyzed
- Jul 21, 2026, 04:30 AM
Related advisories
- @dreamguyxeon/libsignal-node@1.0.1
- topk-js@0.12.0
- json-validator-utils@1.0.1
- habingeer@2.1.6
- tailwind-animationfound@2.3.7
- ts-vitest@1.1.1
- n8n-nodes-probe@1.0.0
- n8n-nodes-api-finder@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.