Launch Week Day 1: Announcing Security Design Review
CRITICAL npm Malware

Malicious code in ltidiconf (npm)

MAL-2026-5767

Published ยท Modified

Description


__

Source: ossf-package-analysis (82f07d72efb0234c99f1db77fa557334d2cf010cd0a7020e470d6e72518c0a5d)

The OpenSSF Package Analysis project identified 'ltidiconf' @ 99.9.1 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

Ready to move

Start Securing

Free, no credit card | First findings in minutes