commonweb-wallet@99.9.1
Malicious code in commonweb-wallet (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
Package commonweb-wallet@99.9.1 is a dependency-confusion attack. It ships a 35-byte stub (index.js = "module.exports = {}") with no real functionality. Its only dependency is a remote tarball URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]5[.]1[.]tgz) hosted on a Google Cloud Storage bucket controlled by the attacker. Installing the package fetches attacker-controlled code from outside the npm registry; the attacker can replace the tarball contents at any time to serve arbitrary code to all installers.
- analyzed by
- Leitwacht
- first seen
- Jul 21, 2026, 04:42 AM
- analyzed
- Jul 21, 2026, 04:43 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.