-= Per source details. Do not edit below this line.=-
package.json declares a single dependency 'ltidisafe' sourced directly from the off-registry URL https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.8.2.tgz, with no registry version range and no integrity hash. On npm install, npm fetches and installs whatever bytes that URL currently serves, executing any lifecycle scripts contained inside the fetched tarball under the installer's account. The GCS bucket host is not tied to any declared publisher of this package, and the fetched content can be changed at any time without a corresponding package republish. The shipped index.js is an empty stub, so the manifest's off-registry fetch is the package's entire effect on the installer. The package name 'unified-platform' at the implausibly high version 99.9.1 is consistent with a dependency-confusion lure targeting an internal name.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021031",
"import_time": "2026-10-05T03:57:40.162769124Z",
"modified_time": "2026-10-05T03:38:21Z",
"sha256": "f8d42d95f6d25be97f23633f7088e06ac7faf2bd7f4fbc20fa85b5be18c90f6b",
"source": "amazon-inspector",
"versions": [
"99.9.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "3249f545805e2b1fbae177702136fad1ac1fb31650cd0d27f890b1289ccf161d",
"tlsh": "b5e07d2006305a334fd901b7485b610bf3718e4f0408bc0c2bdb042c418da7338f935c"
}
],
"package_integrity": [
{
"filename": "unified-platform-99.9.1.tgz",
"hashes": {
"sha1": "d1397c3773ee22415d6df5e88d489e76f2d3396c",
"sha512_sri": "sha512-mTYvA3xMzbiIAi23JC6EU9G9eTLgovwHM81jrZOT3s9EJYOhkLyvDCzSQ/JRnHJZe1kJxz1gfUD1E9QTD4lfDA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/unified-platform/MAL-2026-17566.json"