npm

@web-3d-tool/sdk @99.9.1

Vulnerability report · Last retrieved from osv.dev July 13, 2026 at 6:40 AM UTC

Malicious

OSV ID

MAL-2026-4465

Ecosystem

npm

Summary

@web-3d-tool/sdk is a near-empty package (trivial 35-byte index.js, empty author/description metadata) whose only effect on install is to pull in a dependency declared as a raw tarball URL: "ltidisafe": "https://ltidi.storage.googleapis.com/depenconf/ltidisafe-2.3.1.tgz" (package.json line 9). The bucket ltidi.storage.googleapis.com is unrelated to the @web-3d-tool namespace, is not a versioned npm registry artifact, and the bucket owner can mutate the served tarball at any time without changing this package's version. Any lifecycle hooks (preinstall/install/postinstall) inside the fetched tarball execute on npm install of this package, giving the bucket owner arbitrary code execution on the installer's machine. The combination of hollow lure package + tarball-URL dependency + unrelated anonymous storage bucket + missing publisher metadata is the namespace-abuse dropper shape — the package itself is not the payload, the resolved dependency is.

Source: amazon-inspector (a1e96a726cf0732113215b2026a7a59fc6bf471f86d34153fea3a0e32b275fb5)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.