LWA-2026-6996 MAL-2026-13441 ↗ confirmed malware

consumerweb-creditcollection@99.9.1

Malicious code in consumerweb-creditcollection (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

Package consumerweb-creditcollection@99.9.1 is a dependency-confusion attack. It contains no functional code (empty index.js) but declares a dependency on "ltidisafe" resolved from an external URL: hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]5[.]3[.]tgz. When installed, npm fetches this attacker-controlled tarball, which can execute arbitrary code in the installer's environment. The package name mimics an internal/enterprise naming convention, uses an inflated version number (99.9.1) to win dependency resolution, and has no repository or description.

analyzed by
Leitwacht
first seen
Jul 21, 2026, 04:58 AM
analyzed
Jul 21, 2026, 04:59 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.