connect-contingency@99.9.1
Malicious code in connect-contingency (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
connect-contingency@99.9.1 is a dependency-confusion package with no functional code. Its only dependency is a tarball hosted on an attacker-controlled Google Cloud Storage bucket (ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3.4.7.tgz). When installed, npm fetches and installs arbitrary code from that URL, which the attacker can replace at any time to deliver malware to the installer's environment.
- analyzed by
- Leitwacht
- first seen
- Jul 21, 2026, 04:33 AM
- analyzed
- Jul 21, 2026, 04:34 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.