-= Per source details. Do not edit below this line.=-
The package's package.json declares a dependency ltidisafe resolved not from the npm registry but as a direct tarball URL: https://ltidi.storage.googleapis.com/depenconf/ltidisafe-2.6.2.tgz. On npm install, npm will fetch and install that tarball, executing whatever lifecycle scripts and code it contains on the installer's machine with no audit trail in this package's published source. Several corroborating signals indicate this is dependency-confusion / namespace-abuse tooling rather than a legitimate UI library: the GCS bucket path literally contains the string depenconf (a common shorthand for dependency-confusion); the package version is 99.9.1, the high-version-squat pattern used to outrank a private internal package of the same name; package metadata (author, description) is empty; and the package's own index.js is near-empty, providing no library functionality consistent with the @druids/ui name. The installer-side harm is the silent inclusion of an attacker-controlled, registry-unaudited transitive into the dependency tree.
{
"malicious-packages-origins": [
{
"versions": [
"99.9.1"
],
"id": "IN-MAL-2026-004138",
"modified_time": "2026-05-22T06:09:23Z",
"import_time": "2026-05-26T05:52:00.589901744Z",
"sha256": "071ce35c0d6a17c606e5448f4c485228df973342935b0a11519304050877edf5",
"source": "amazon-inspector"
},
{
"versions": [
"99.9.1"
],
"id": "IN-MAL-2026-004139",
"modified_time": "2026-05-22T06:09:24Z",
"import_time": "2026-05-26T05:52:00.764660457Z",
"sha256": "bffabf1852f8882e1b5442ad9d5021ed43f90f13a48f4151e898709880ee08fe",
"source": "amazon-inspector"
}
]
}"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@druids/ui/MAL-2026-4385.json"
[
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
}
]
{
"domains": [
"ltidi.storage.googleapis.com"
],
"package_integrity": [
{
"hashes": {
"sha1": "3927ace5a62df0697b87ea62b482277514dc92d6",
"sha512_sri": "sha512-R7Dsef75FpClymBSZ8cj89A+CXjxXwY2PhEuQTRcE2sg8YVITWaA/+S8rqLjWk93fydUG1tiTiRz0UdEi1P6pA=="
},
"filename": "ui-99.9.1.tgz"
}
],
"evidence_files": [
{
"path": "package.json",
"sha256": "c7dd2325f769b7b1b21eb667d7173d4cc052700d983055b32a8d9c8ed78acf3d",
"tlsh": "3ee0c2344a6166334ec621b68c2a955bf3b18e5f4419bc0d6aeb441c829da7328f939e"
}
]
}