Logo
npm

unified-platform@99.9.1

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC

Malicious

OSV ID

MAL-2026-17566

Ecosystem

npm

Summary

package.json declares a single dependency 'ltidisafe' sourced directly from the off-registry URL https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.8.2.tgz, with no registry version range and no integrity hash. On npm install, npm fetches and installs whatever bytes that URL currently serves, executing any lifecycle scripts contained inside the fetched tarball under the installer's account. The GCS bucket host is not tied to any declared publisher of this package, and the fetched content can be changed at any time without a corresponding package republish. The shipped index.js is an empty stub, so the manifest's off-registry fetch is the package's entire effect on the installer. The package name 'unified-platform' at the implausibly high version 99.9.1 is consistent with a dependency-confusion lure targeting an internal name.

Source: amazon-inspector (f8d42d95f6d25be97f23633f7088e06ac7faf2bd7f4fbc20fa85b5be18c90f6b)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.