consumerweb-creditcollection@99.9.1
Malicious code in consumerweb-creditcollection (npm)
Analysis
Package consumerweb-creditcollection@99.9.1 is a dependency-confusion attack. It contains no functional code (empty index.js) but declares a dependency on "ltidisafe" resolved from an external URL: hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]5[.]3[.]tgz. When installed, npm fetches this attacker-controlled tarball, which can execute arbitrary code in the installer's environment. The package name mimics an internal/enterprise naming convention, uses an inflated version number (99.9.1) to win dependency resolution, and has no repository or description.
- analyzed by
- Leitwacht
- first seen
- Jul 21, 2026, 04:58 AM
- analyzed
- Jul 21, 2026, 04:59 AM
Related advisories
- cxpw-offers@99.9.1
- app-data-ist@2.1.6
- requestor-util@99.9.1
- @dreamguyxeon/libsignal-node@1.0.1
- topk-js@0.12.0
- json-validator-utils@1.0.1
- habingeer@2.1.6
- tailwind-animationfound@2.3.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.