depcruise-wrap-stream-in-html@99.9.1
Malicious code in depcruise-wrap-stream-in-html (npm)
Analysis
The package is an empty shell (index.js exports an empty object) that declares a dependency named "ltidisafe" fetched at install time from a non-registry Google Cloud Storage URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]7[.]5[.]tgz). The package name is a combosquat of the legitimate dependency-cruiser tool, and the off-registry dependency is pulled from a CDN path under "depenconf", indicating a dependency-confusion supply-chain attack where the real payload is delivered via the external dependency rather than the package's own code.
- analyzed by
- Leitwacht
- first seen
- Aug 15, 2026, 02:32 PM
- analyzed
- Aug 15, 2026, 02:33 PM
Related advisories
- depcruise-baseline@99.9.1
- gunzip-js@99.9.1
- @mrzkyzdnii/baileys@0.3.18-mrzkyzdnii.2
- tailwind-utility-kit@1.3.2
- postcss-initialize-provider@3.0.4
- mutex-thread@1.3.0
- tailwind-plugin-kit@1.3.2
- tailwind-toolkit@1.3.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.