MAL-2026-13441

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/consumerweb-creditcollection/MAL-2026-13441.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-13441
Published
2026-08-06T16:18:36Z
Modified
2026-08-06T23:50:08.626587199Z
Summary
Malicious code in consumerweb-creditcollection (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (d1d673b014d7769d23ec9252c38424a3d1e2b400756cafa605f65383d93da348)

consumerweb-creditcollection@99.9.1 is a hollow package whose main index.js exports an empty object. Its sole runtime effect is pulling in a dependency ltidisafe pinned to an arbitrary tarball URL on a third-party Google Cloud Storage bucket (https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.5.3.tgz) rather than an npm registry entry. Installing this package causes npm to download and install code from that off-registry URL, which is outside npm registry scanning. The depenconf path segment, the internal-sounding package name, and the high version number 99.9.1 are consistent with a dependency-confusion / namespace-squat delivery vector where the lure package's only purpose is to force resolution of attacker-hosted code into the installer's dependency tree.

Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2026-08-06T16:18:36Z",
            "id": "IN-MAL-2026-016671",
            "import_time": "2026-08-06T18:09:03.984797741Z",
            "versions": [
                "99.9.1"
            ],
            "source": "amazon-inspector",
            "sha256": "d1d673b014d7769d23ec9252c38424a3d1e2b400756cafa605f65383d93da348"
        }
    ]
}
References
Credits

Affected packages

npm / consumerweb-creditcollection

Package

Name
consumerweb-creditcollection
View open source insights on deps.dev
Purl
pkg:npm/consumerweb-creditcollection

Affected ranges

Affected versions

99.*
99.9.1

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    }
]
indicators
{
    "package_integrity": [
        {
            "hashes": {
                "sha512_sri": "sha512-ugY7+J7m7mA/Qg6F6IBLZH2hOu3so54/dFqfjLYOIJkOV2E5LlfdAdPSiQa8EVdO36GZPhiCcWclQT6M1rm4aQ==",
                "sha1": "0b27dd11d73576effed208f751e696e11c5cde90"
            },
            "filename": "consumerweb-creditcollection-99.9.1.tgz"
        }
    ],
    "evidence_files": [
        {
            "path": "package.json",
            "tlsh": "7be07d204a2066334ec911f2482b619bf3708e8f0404bc0c6edf042c41aca732cf935c",
            "sha256": "067d8a16b2d3fd4f9782d2e045b5a337f30c1b0c85e3936bd5a5956838f7b7af"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/consumerweb-creditcollection/MAL-2026-13441.json"