MAL-2026-13441
Malicious code in consumerweb-creditcollection (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (d1d673b014d7769d23ec9252c38424a3d1e2b400756cafa605f65383d93da348) consumerweb-creditcollection@99.9.1 is a hollow package whose main index.js exports an empty object. Its sole runtime effect is pulling in a dependency `ltidisafe` pinned to an arbitrary tarball URL on a third-party Google Cloud Storage bucket (`https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.5.3.tgz`) rather than an npm registry entry. Installing this package causes npm to download and install code from that off-registry URL, which is outside npm registry scanning. The `depenconf` path segment, the internal-sounding package name, and the high version number 99.9.1 are consistent with a dependency-confusion / namespace-squat delivery vector where the lure package's only purpose is to force resolution of attacker-hosted code into the installer's dependency tree.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for consumerweb-creditcollection (npm). Pin to a known-safe version or switch to an alternative.