@cr-invested-ui-components/chart@99.9.1
Malicious code in @cr-invested-ui-components/chart (npm)
Analysis
Dependency-confusion package @cr-invested-ui-components/chart@99.9.1 impersonates a UI component library via a scoped name and version-squat (99.9.1) to outrank legitimate internal packages. The package is an empty stub with no real functionality (module.exports = {}). It declares a dependency on an external non-registry tarball at hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]4[.]2[.]tgz, which delivers arbitrary code from a CDN when the dependency is resolved during install. The package has no repository, no description, and no README.
- analyzed by
- Leitwacht
- first seen
- Jul 15, 2026, 05:15 PM
- analyzed
- Jul 15, 2026, 05:16 PM
Related advisories
- utils-style-engine@10.2.4
- dilxztech@1.0.0
- po-ops-local-dev@99.9.1
- webrix-docs1@10.2.11
- lusha-iam-widgets@1.5.2
- driftpin@1.0.0
- ryan-pdf-js@99.9.1
- chai-as-assured@7.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.