Logo
npm

@pinecone-experience/messages@99.9.1

Vulnerability report · Last retrieved from osv.dev October 6, 2026 at 2:31 PM UTC

Malicious

OSV ID

MAL-2026-17631

Ecosystem

npm

Summary

package.json declares its sole dependency ltidisafe as a bare HTTPS tarball URL (https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.8.3.tgz) hosted on a third-party Google Cloud Storage bucket rather than a registry version range. On npm install, npm fetches that URL and installs whatever bytes it returns, executing any lifecycle scripts inside the fetched tarball on the installer's host with no version pin, no hash, and no integrity check — whoever controls that bucket controls code executed at install time. The shipped index.js is an empty stub (module.exports = {}), so the package's only effect is to pull in the off-registry archive. The package is published under the @pinecone-experience scope at version 99.9.1 — an implausibly high version under a vendor-looking scope, matching the dependency-confusion shape where a high version is used to win resolution against an internal package of the same name.

Source: amazon-inspector (078ce187b38122a7eff5def33454871232cdd38bde7d35e7ee1968d0e98cd45c)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.