MAL-2026-13976
Malicious code in check-audit (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (723c3dbef875102d9d461c655737b930ea9f58f2a5555bd254d954d7003eacf5) check-audit@99.9.1 is an otherwise empty package (no author, no description, no meaningful code) whose only effect on install is to pull a dependency named `ltidisafe` from an arbitrary Google Cloud Storage URL: `https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.6.5.tgz`. This URL is not the npm registry and is not tied to any declared publisher of check-audit. The tarball contents are mutable and bypass registry-side scanning; whatever code and lifecycle scripts it ships execute in the installer's node_modules on `npm install`. The version number (99.9.1) and hollow package contents are consistent with a lure/dropper whose sole purpose is to pull attacker-controllable code into the dependency tree at install time.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for check-audit (npm). Pin to a known-safe version or switch to an alternative.