cxpw-offers@99.9.1
Malicious code in cxpw-offers (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
Dependency-confusion package. cxpw-offers@99.9.1 is a minimal stub (empty index.js) that declares a single dependency resolved from an external URL: hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]4[.]9[.]tgz. The high version number on a generic name is designed to take priority over a private internal package with the same name. The remote tarball is attacker-controlled and can deliver arbitrary code on install.
- analyzed by
- Leitwacht
- first seen
- Jul 21, 2026, 04:39 AM
- analyzed
- Jul 21, 2026, 04:40 AM
Related advisories
- app-data-ist@2.1.6
- requestor-util@99.9.1
- @dreamguyxeon/libsignal-node@1.0.1
- topk-js@0.12.0
- json-validator-utils@1.0.1
- habingeer@2.1.6
- tailwind-animationfound@2.3.7
- ts-vitest@1.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.