Your RSA-2048 keys break in 2030. Find every one of them before attackers do.See CBOMkit
Malicious package
ltidiconfnpm
Malicious code in ltidiconf (npm) Remove it immediately and rotate any exposed credentials.
MAL-2026-5767
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall ltidiconf
What this malware does
The OpenSSF Package Analysis project identified 'ltidiconf' @ 99.9.1 (npm) as malicious.
It is considered malicious because:
- The package communicates with a domain associated with malicious activity.
Malicious versions
99.9.1
Indicators of compromise (SHA-256)
82f07d72efb0234c99f1db77fa557334d2cf010cd0a7020e470d6e72518c0a5d
Frequently asked questions
No. ltidiconf on npm has been identified as a malicious package (version 99.9.1 flagged). It should be removed immediately — do not install or keep it in your dependency tree.
Credits
- OpenSSF: Package Analysis · finder
Scan your dependencies
O3 Security blocks malicious packages like this at install time and in CI.
Supply-chain protection