LWA-2026-6971 MAL-2026-10966 ↗ confirmed malware

commonweb-card@99.9.1

Malicious code in commonweb-card (npm)

Analysis

A cluster of empty packages (commonweb-moneymovement, commonweb-wallet, commonweb-balance, commonweb-card) all at version 99.9.1, each containing only a stub index.js that exports an empty object. The sole purpose of each package is to declare a dependency on an external tarball hosted at ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-*.tgz. When npm installs the package, it fetches and installs the external tarball, which the attacker controls and can swap at any time to deliver arbitrary code into the install chain. The package names combosquat financial terminology to trick developers into installing them.

analyzed by
Leitwacht
first seen
Jul 21, 2026, 04:54 AM
analyzed
Jul 21, 2026, 05:01 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.