commonweb-rewards@99.9.1
Malicious code in commonweb-rewards (npm)
Analysis
Dependency-confusion packages published at version 99.9.1 with names impersonating internal enterprise modules (commonweb-rewards, consumerweb-creditcollection, commonweb-moneymovement, cxpw-offers, requestor-util). Each package contains an empty index.js and declares a single dependency pointing to an external tarball hosted at ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-*.tgz. When installed, npm fetches and extracts the external tarball, which delivers the actual payload. The external tarball URLs are: hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]5[.]5[.]tgz, hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]5[.]3[.]tgz, hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]5[.]4[.]tgz, hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]4[.]9[.]tgz, hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]4[.]6[.]tgz.
- analyzed by
- Leitwacht
- first seen
- Jul 21, 2026, 05:02 AM
- analyzed
- Jul 21, 2026, 05:03 AM
Related advisories
- consumerweb-creditcollection@99.9.1
- cxpw-offers@99.9.1
- app-data-ist@2.1.6
- requestor-util@99.9.1
- @dreamguyxeon/libsignal-node@1.0.1
- @offa-uwk/offa-uwk@999.0.6
- vaparklink@1.0.0
- topk-js@0.12.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.