check-audit @99.9.1
Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 2:31 AM UTC
OSV ID
MAL-2026-13976
Ecosystem
npm
Summary
check-audit@99.9.1 is an otherwise empty package (no author, no description, no meaningful code) whose only effect on install is to pull a dependency named ltidisafe from an arbitrary Google Cloud Storage URL: https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.6.5.tgz . This URL is not the npm registry and is not tied to any declared publisher of check-audit. The tarball contents are mutable and bypass registry-side scanning; whatever code and lifecycle scripts it ships execute in the installer's node_modules on npm install . The version number (99.9.1) and hollow package contents are consistent with a lure/dropper whose sole purpose is to pull attacker-controllable code into the dependency tree at install time.
Source: amazon-inspector (723c3dbef875102d9d461c655737b930ea9f58f2a5555bd254d954d7003eacf5)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.