Logo
npm

risk-detection@99.9.1

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC

Malicious

OSV ID

MAL-2026-17563

Ecosystem

npm

Summary

package.json declares a dependency ltidisafe whose source is an off-registry tarball URL (https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.8.1.tgz) rather than a semver range on the npm registry. The shipped index.js is an empty stub (module.exports = {}), so the manifest URL is the entire install-time surface. On npm install, npm fetches whatever bytes that URL returns — unpinned, no integrity hash, no registry publisher check — installs the resulting package, and runs any lifecycle scripts inside it. Whoever controls that bucket path controls code execution on the installer's machine.

Source: amazon-inspector (4b74a904a25687bbc34ad321ea019c5083f9a3651457750ed36207a209798f77)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.