VDB
EN

MAL-2026-13440

Malicious code in connect-contingency (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (b3a03c555705f2bfa2e63b96e9ea5740196d1ea5ca8be0f1acce290c771f01ea) connect-contingency@99.9.1 is a hollow package whose index.js is an empty stub. Its package.json declares its sole dependency `ltidisafe` as a direct tarball URL on an anonymous Google Cloud Storage bucket: `https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.4.7.tgz`. On `npm install`, npm downloads that tarball from a non-registry, non-publisher host outside registry integrity/audit coverage and installs it, executing any lifecycle scripts (preinstall/install/postinstall) it declares. The package name, an inflated 99.9.x version characteristic of dependency-confusion staging, the empty main, and the `/depenconf/` URL path together indicate a dependency-confusion lure whose only effect on install is to pull attacker-controlled code into the installer's environment.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / connect-contingency

No fixed version published yet for connect-contingency (npm). Pin to a known-safe version or switch to an alternative.

참고