MAL-2026-13987
Malicious code in resolve-audit (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (86b902b4dc4c2187bb95548ed903dfea70ea626ba5450f031c2cb27b3639dd1c) resolve-audit@99.9.1 is a stub package (index exports an empty object) whose package.json declares its only dependency `ltidisafe` as a direct HTTPS tarball URL: https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.6.6.tgz. On `npm install`, npm fetches this arbitrary tarball from an anonymous, mutable Google Cloud Storage bucket (path segment `depenconf`, a dependency-confusion marker) rather than resolving through the npm registry, with no version-by-hash pinning. Any lifecycle scripts inside that tarball execute on the installer. The version number 99.9.1 is characteristic of dependency-confusion/version-squat lures designed to win resolution against a private-registry package of the same name.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for resolve-audit (npm). Pin to a known-safe version or switch to an alternative.