MAL-2026-10965
Malicious code in requestor-util (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (d8a60f357ab63e9818e450e4e4aec3dcf1b08d1242931ad5ad8468a460ee82ba) requestor-util@99.9.1 is a hollow wrapper (empty index.js, placeholder 99.9.1 version) whose only effect on install is to resolve a dependency declared as a direct tarball URL: "ltidisafe": "https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.4.6.tgz". npm install fetches whatever bytes currently live at that mutable Google Cloud Storage URL and executes any preinstall/install/postinstall lifecycle scripts contained in that tarball on the installer's machine. The URL is not on the npm registry (bypassing registry-side scanning) and is controlled by whoever owns the GCS bucket, who can swap the payload at any time without republishing the wrapper. The hollow-main + off-registry-tarball-dependency shape matches the dropper-lure pattern: the wrapper's function is to force resolution of an attacker-mutable external artifact into every installer's dependency tree.
## Source: ossf-package-analysis (6d4229671aa9a57f0ffbe61cd9ebe925c0874f55dd72d15f43adff096d0cf3f0) The OpenSSF Package Analysis project identified 'requestor-util' @ 99.9.1 (npm) as malicious.
It is considered malicious because:
- The package communicates with a domain associated with malicious activity.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for requestor-util (npm). Pin to a known-safe version or switch to an alternative.