depcruise-baseline@99.9.1
Malicious code in depcruise-baseline (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
depcruise-baseline@99.9.1 is an empty stub package (index.js exports an empty object, no install scripts) that declares a single dependency, ltidisafe, resolved from a non-registry Google Cloud Storage URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]7[.]4[.]tgz) instead of the npm registry. Installing the package fetches and executes a tarball from this attacker-controlled host, delivering a remote payload outside the normal registry supply chain.
- analyzed by
- Leitwacht
- first seen
- Aug 15, 2026, 02:31 PM
- analyzed
- Aug 15, 2026, 02:32 PM
Related advisories
- gunzip-js@99.9.1
- @mrzkyzdnii/baileys@0.3.18-mrzkyzdnii.2
- tailwind-utility-kit@1.3.2
- postcss-initialize-provider@3.0.4
- mutex-thread@1.3.0
- tailwind-plugin-kit@1.3.2
- tailwind-toolkit@1.3.2
- @cdnshell/loader@0.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.