@smwebserver/static@99.9.1
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC
OSV ID
MAL-2026-17456
Ecosystem
npm
Summary
The package ships an effectively empty index.js and its only real content is a manifest-level dependency sourced from an arbitrary HTTPS URL rather than a registry version range: dependencies.ltidisafe is set to https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.7.9.tgz. On npm install, npm fetches that tarball and installs it, running any lifecycle scripts it contains, with no version pin, no integrity hash, and no signature check. The bucket host is not a publisher-controlled domain tied to this package, and the contents at that URL can be swapped at any time by whoever owns the bucket. The absence of lifecycle scripts in this package's own package.json does not mitigate the issue, because the fetched tarball's scripts are what execute. Installing this package therefore delegates full install-time code execution on the installer's machine to a mutable, off-registry source.
Source: amazon-inspector (3de0cc583ad7f0166991a10b69426eabbd42d6eaef796e7ea078cf76e9a741e7)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.