depcruise-fmt@99.9.1
Malicious code in depcruise-fmt (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
depcruise-fmt@99.9.1 is a stub package (its only code is `module.exports = {}`) that declares a single dependency, `ltidisafe`, fetched at install time from a non-registry Google Cloud Storage CDN URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]7[.]3[.]tgz). The package name impersonates the dependency-cruiser tool's CLI. Installing this package pulls and installs the remote tarball from the attacker-controlled CDN rather than from the npm registry, delivering the payload as a dependency.
- analyzed by
- Leitwacht
- first seen
- Aug 15, 2026, 02:31 PM
- analyzed
- Aug 15, 2026, 02:32 PM
Related advisories
- gunzip-js@99.9.1
- require-i18next@20.0.0
- @mrzkyzdnii/baileys@0.3.18-mrzkyzdnii.2
- @finaxis/common-js@0.3.3
- postcss-initialize-provider@3.0.4
- alelo-sdk@99.0.0
- @hzero-front-ui/core@99.99.99
- tailwind-toolkit@1.3.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.