-= Per source details. Do not edit below this line.=-
consumerweb-creditcollection@99.9.1 is a hollow package whose main index.js exports an empty object. Its sole runtime effect is pulling in a dependency ltidisafe pinned to an arbitrary tarball URL on a third-party Google Cloud Storage bucket (https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.5.3.tgz) rather than an npm registry entry. Installing this package causes npm to download and install code from that off-registry URL, which is outside npm registry scanning. The depenconf path segment, the internal-sounding package name, and the high version number 99.9.1 are consistent with a dependency-confusion / namespace-squat delivery vector where the lure package's only purpose is to force resolution of attacker-hosted code into the installer's dependency tree.
{
"malicious-packages-origins": [
{
"modified_time": "2026-08-06T16:18:36Z",
"id": "IN-MAL-2026-016671",
"import_time": "2026-08-06T18:09:03.984797741Z",
"versions": [
"99.9.1"
],
"source": "amazon-inspector",
"sha256": "d1d673b014d7769d23ec9252c38424a3d1e2b400756cafa605f65383d93da348"
}
]
}[
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
{
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-ugY7+J7m7mA/Qg6F6IBLZH2hOu3so54/dFqfjLYOIJkOV2E5LlfdAdPSiQa8EVdO36GZPhiCcWclQT6M1rm4aQ==",
"sha1": "0b27dd11d73576effed208f751e696e11c5cde90"
},
"filename": "consumerweb-creditcollection-99.9.1.tgz"
}
],
"evidence_files": [
{
"path": "package.json",
"tlsh": "7be07d204a2066334ec911f2482b619bf3708e8f0404bc0c6edf042c41aca732cf935c",
"sha256": "067d8a16b2d3fd4f9782d2e045b5a337f30c1b0c85e3936bd5a5956838f7b7af"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/consumerweb-creditcollection/MAL-2026-13441.json"