cxpw-offers@99.9.1
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 5:38 AM UTC
OSV ID
MAL-2026-10971
Ecosystem
npm
Summary
cxpw-offers ships an empty index.js and declares its only dependency ltidisafe as a direct tarball URL at https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.4.9.tgz, bypassing the npm registry. On npm install, npm fetches and installs that off-registry tarball without integrity/hash pinning, executing whatever lifecycle scripts and module code it contains on the installer's machine. The package has no functional code of its own — the sole install-time effect is resolving and running attacker-controlled bytes from a third-party bucket. The path segment depenconf and the hollow main module are consistent with a dependency-confusion drop shape.
Source: amazon-inspector (2288ef5dfb841556f7ba4907a025270dfda3439820215b7d98e644afca78a306)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.