MAL-2026-17566

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/unified-platform/MAL-2026-17566.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17566
Published
2026-10-05T03:38:21Z
Modified
2026-10-05T04:15:06Z
Summary
Malicious code in unified-platform (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (f8d42d95f6d25be97f23633f7088e06ac7faf2bd7f4fbc20fa85b5be18c90f6b)

package.json declares a single dependency 'ltidisafe' sourced directly from the off-registry URL https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.8.2.tgz, with no registry version range and no integrity hash. On npm install, npm fetches and installs whatever bytes that URL currently serves, executing any lifecycle scripts contained inside the fetched tarball under the installer's account. The GCS bucket host is not tied to any declared publisher of this package, and the fetched content can be changed at any time without a corresponding package republish. The shipped index.js is an empty stub, so the manifest's off-registry fetch is the package's entire effect on the installer. The package name 'unified-platform' at the implausibly high version 99.9.1 is consistent with a dependency-confusion lure targeting an internal name.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-021031",
            "import_time":  "2026-10-05T03:57:40.162769124Z",
            "modified_time":  "2026-10-05T03:38:21Z",
            "sha256":  "f8d42d95f6d25be97f23633f7088e06ac7faf2bd7f4fbc20fa85b5be18c90f6b",
            "source":  "amazon-inspector",
            "versions":  [
                "99.9.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / unified-platform

Package

Name
unified-platform
View open source insights on deps.dev
Purl
pkg:npm/unified-platform

Affected ranges

Affected versions

99.*
99.9.1

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "3249f545805e2b1fbae177702136fad1ac1fb31650cd0d27f890b1289ccf161d",
            "tlsh":  "b5e07d2006305a334fd901b7485b610bf3718e4f0408bc0c2bdb042c418da7338f935c"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "unified-platform-99.9.1.tgz",
            "hashes":  {
                "sha1":  "d1397c3773ee22415d6df5e88d489e76f2d3396c",
                "sha512_sri":  "sha512-mTYvA3xMzbiIAi23JC6EU9G9eTLgovwHM81jrZOT3s9EJYOhkLyvDCzSQ/JRnHJZe1kJxz1gfUD1E9QTD4lfDA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/unified-platform/MAL-2026-17566.json"