LWA-2026-11330 MAL-2026-14054 ↗ confirmed malware

depcruise-fmt@99.9.1

Malicious code in depcruise-fmt (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

depcruise-fmt@99.9.1 is a stub package (its only code is `module.exports = {}`) that declares a single dependency, `ltidisafe`, fetched at install time from a non-registry Google Cloud Storage CDN URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]7[.]3[.]tgz). The package name impersonates the dependency-cruiser tool's CLI. Installing this package pulls and installs the remote tarball from the attacker-controlled CDN rather than from the npm registry, delivering the payload as a dependency.

analyzed by
Leitwacht
first seen
Aug 15, 2026, 02:31 PM
analyzed
Aug 15, 2026, 02:32 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.