Logo
npm

liferay-workspace-scripts@99.9.1

Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 3:53 PM UTC

Malicious

OSV ID

MAL-2026-17772

Ecosystem

npm

Summary

package.json declares the sole dependency ltidisafe as a bare HTTPS tarball URL (https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.8.5.tgz) instead of a registry version range. On npm install, npm fetches that URL and installs whatever bytes it returns, executing any lifecycle scripts inside the fetched package, with no version pin and no integrity hash. The shipped index.js is an empty stub, so the manifest is the entire published surface. The package name mirrors Liferay-ecosystem tooling and the version 99.9.1 is implausibly high for a legitimate release, consistent with a dependency-confusion lure designed to win resolution against an internal package name. Whoever controls the Google Cloud Storage bucket controls code executed on every installer's machine at install time.

Source: amazon-inspector (3395e72ef77703732691fce21359206afea7598fb3d1dab29ded4b2e1c7cd28f)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.