{"id":"MAL-2026-10422","summary":"Malicious code in sso-users-detection (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (dc80441472ec24451f83aebdc186d5bc532ddadaac8888d3d30b72c17c94f993)\nsso-users-detection@99.9.1 is a hollow package (main exports `{}`, empty author/description, inflated 99.9.1 version) whose sole effect on install is to pull a runtime dependency named `ltidisafe` from a raw tarball URL on a third-party Google Cloud Storage bucket (`https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.3.1.tgz`) instead of the npm registry. On `npm install`, npm fetches and installs that tarball, whose contents and lifecycle scripts (preinstall/install/postinstall) are entirely controlled by whoever owns the bucket and bypass npm registry scanning. The `depenconf` path segment, the inflated version number, and the empty index are consistent with a dependency-confusion lure whose only purpose is to smuggle attacker-controlled code into installer dependency trees.\n","modified":"2026-07-13T07:47:03.597572972Z","published":"2026-07-13T07:00:55Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["99.9.1"],"id":"IN-MAL-2026-009852","import_time":"2026-07-13T07:40:13.326033358Z","modified_time":"2026-07-13T07:00:55Z","sha256":"dc80441472ec24451f83aebdc186d5bc532ddadaac8888d3d30b72c17c94f993"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/sso-users-detection/v/99.9.1"}],"affected":[{"package":{"name":"sso-users-detection","ecosystem":"npm","purl":"pkg:npm/sso-users-detection"},"versions":["99.9.1"],"database_specific":{"indicators":{"package_integrity":[{"filename":"sso-users-detection-99.9.1.tgz","hashes":{"sha1":"7673ab77df6a0f2c616d5bd631ef01aea163262c","sha512_sri":"sha512-Bix4rPxR1aAPbdU3p9iJFce4U81dZOHq5M3Q/zVn5TpegxOFS7uCaXaaXMzWAzo2TCH2XC0GT1/BmA6O/SiePA=="}}],"evidence_files":[{"path":"package.json","sha256":"c780a7e922260538ac7a8fa7d9598d22694227c9e03532caea9caf8045e0f778","tlsh":"aae072200a2566334eda11b2882b651bf3708e5f0818bc0c5bef042c418df7b28fa26d"}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/sso-users-detection/MAL-2026-10422.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}