commonweb-card@99.9.1
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 3:37 AM UTC
OSV ID
MAL-2026-10966
Ecosystem
npm
Summary
commonweb-card@99.9.1 ships an effectively empty main module (index.js exports an empty object) and its package.json declares a dependency 'ltidisafe' whose version specifier is a direct HTTPS tarball URL to an anonymous Google Cloud Storage bucket: https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.5.2.tgz. On npm install, npm downloads and installs the tarball at that URL and executes any lifecycle scripts (preinstall/install/postinstall) and top-level require side effects it contains. The tarball host is not the npm registry, not a documented vendor publisher, and not tied to the wrapper package's stated identity; its contents are controlled solely by whoever owns the GCS bucket and can be mutated at any time without a package version bump. The high version number (99.9.1) combined with a hollow wrapper and a remote tarball dependency matches the dependency-confusion loader pattern.
Source: amazon-inspector (be45f481316bef278d1accb9df9fb9e30f5789c2c783c749c7f8903868130a71)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.