osv:MAL-2026-17566
Malicious code in unified-platform (npm)
Malicious package
unified-platform"unified-platform" is registered as malicious in the npm repository. Anyone who installed the package should uninstall it immediately, isolate affected environments, and rotate credentials that were present during installation.
Affected versions (1)
- 99.9.1
purl: pkg:npm/unified-platform
Sources (1)
amazon-inspectorIN-MAL-2026-0210312026-10-05 03:38 UTCVersions from this source: 99.9.1
sha256: f8d42d95f6d25be97f23633f7088e06ac7faf2bd7f4fbc20fa85b5be18c90f6b
The OSSF `malicious-packages` namespace lists packages flagged as malicious by static analysis or sandbox detonation. An entry here is a confirmed finding, not a suspicion.
Description
-= Per source details. Do not edit below this line.=-
Source: amazon-inspector (f8d42d95f6d25be97f23633f7088e06ac7faf2bd7f4fbc20fa85b5be18c90f6b)
package.json declares a single dependency 'ltidisafe' sourced directly from the off-registry URL https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.8.2.tgz, with no registry version range and no integrity hash. On npm install, npm fetches and installs whatever bytes that URL currently serves, executing any lifecycle scripts contained inside the fetched tarball under the installer's account. The GCS bucket host is not tied to any declared publisher of this package, and the fetched content can be changed at any time without a corresponding package republish. The shipped index.js is an empty stub, so the manifest's off-registry fetch is the package's entire effect on the installer. The package name 'unified-platform' at the implausibly high version 99.9.1 is consistent with a dependency-confusion lure targeting an internal name.
Source: OSV