LWA-2026-11331 MAL-2026-14053 ↗ confirmed malware

depcruise-baseline@99.9.1

Malicious code in depcruise-baseline (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

depcruise-baseline@99.9.1 is an empty stub package (index.js exports an empty object, no install scripts) that declares a single dependency, ltidisafe, resolved from a non-registry Google Cloud Storage URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]7[.]4[.]tgz) instead of the npm registry. Installing the package fetches and executes a tarball from this attacker-controlled host, delivering a remote payload outside the normal registry supply chain.

analyzed by
Leitwacht
first seen
Aug 15, 2026, 02:31 PM
analyzed
Aug 15, 2026, 02:32 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.