LWA-2026-11332 confirmed malware

depcruise-wrap-stream-in-html@99.9.1

Malicious code in depcruise-wrap-stream-in-html (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

The package is an empty shell (index.js exports an empty object) that declares a dependency named "ltidisafe" fetched at install time from a non-registry Google Cloud Storage URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]7[.]5[.]tgz). The package name is a combosquat of the legitimate dependency-cruiser tool, and the off-registry dependency is pulled from a CDN path under "depenconf", indicating a dependency-confusion supply-chain attack where the real payload is delivered via the external dependency rather than the package's own code.

analyzed by
Leitwacht
first seen
Aug 15, 2026, 02:32 PM
analyzed
Aug 15, 2026, 02:33 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.