@webd-infra/query-designer-domain @99.9.1
Vulnerability report · Last retrieved from osv.dev July 19, 2026 at 4:07 AM UTC
OSV ID
MAL-2026-5431
Ecosystem
npm
Summary
The package's package.json declares its only dependency ltidisafe as a direct tarball URL: https://ltidi.storage.googleapis.com/depenconf/ltidisafe-2.8.3.tgz . On npm install , npm fetches this tarball from a Google Cloud Storage bucket (not the npm registry) and runs whatever lifecycle scripts it contains. The bucket owner — not an npm publisher with registry-side accountability — controls exactly which bytes get executed, and the tarball contents at that URL can change at any time. Supporting indicators: the package has empty author and description fields, the version 99.9.1 is the canonical dependency-confusion sentinel used in research/PoC packages, and the bucket path segment is the literal string depenconf . The package itself ships no other runtime code — its sole effect on installers is resolving and executing this off-registry tarball.
Source: amazon-inspector (1c7713f23c6a0044172532693bc43aee0d785a980fc5c83ba1f773af9082e3b3)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.