LWA-2026-6967 MAL-2026-13440 ↗ confirmed malware

connect-contingency@99.9.1

Malicious code in connect-contingency (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

connect-contingency@99.9.1 is a dependency-confusion package with no functional code. Its only dependency is a tarball hosted on an attacker-controlled Google Cloud Storage bucket (ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3.4.7.tgz). When installed, npm fetches and installs arbitrary code from that URL, which the attacker can replace at any time to deliver malware to the installer's environment.

analyzed by
Leitwacht
first seen
Jul 21, 2026, 04:33 AM
analyzed
Jul 21, 2026, 04:34 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.