LWA-2026-6817 MAL-2026-11435 ↗ confirmed malware

@cr-invested-ui-components/chart@99.9.1

Malicious code in @cr-invested-ui-components/chart (npm)

T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise

Analysis

Dependency-confusion package @cr-invested-ui-components/chart@99.9.1 impersonates a UI component library via a scoped name and version-squat (99.9.1) to outrank legitimate internal packages. The package is an empty stub with no real functionality (module.exports = {}). It declares a dependency on an external non-registry tarball at hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]4[.]2[.]tgz, which delivers arbitrary code from a CDN when the dependency is resolved during install. The package has no repository, no description, and no README.

analyzed by
Leitwacht
first seen
Jul 15, 2026, 05:15 PM
analyzed
Jul 15, 2026, 05:16 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.