Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in depcruise-wrap-stream-in-html (npm)

depcruise-wrap-stream-in-html@99.9.1 is a malicious npm package that mimics an internal helper of dependency-cruiser. It is a hollow package that downloads and executes arbitrary code from a Google Cloud Storage bucket during installation.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any developer or CI/CD system that installed depcruise-wrap-stream-in-html@99.9.1
Ecosystems
Attack vectors
Affected entities
  • depcruise-wrap-stream-in-html · 99.9.1

depcruise-wrap-stream-in-html@99.9.1 was published to npm as a malicious package designed to exploit dependency confusion. The package name closely mimics an internal helper module of the legitimate dependency-cruiser project, making it a likely target for typosquatting or confusion attacks.

The package itself is hollow—its index.js exports an empty object—but its true payload is in a runtime dependency on ltidisafe, which is resolved from an arbitrary HTTPS tarball hosted on Google Cloud Storage at https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.7.5.tgz. This URL is unrelated to any known publisher of dependency-cruiser.

During npm install, npm automatically downloads and installs the tarball into node_modules. Any lifecycle scripts within the tarball execute on the installer's machine with the privileges of the installing user. The bucket owner can swap the tarball contents at any time without republishing to npm, bypassing registry scanning and version pinning guarantees.

The incident was identified by the OpenSSF's malicious-packages project and reported via GitHub Security Advisory GHSA-8r7w-6hqf-4x5p.

Indicators of compromise

Packages
  • depcruise-wrap-stream-in-html@99.9.1
Domains
  • ltidi.storage.googleapis.com
Hashes
  • bce3c6c9707df3626f30cbf434aa298d1df5cda4cf7b06b76ad4c92d04004a1c

Remediation

  • Remove depcruise-wrap-stream-in-html from all package.json files and lock files
  • Audit npm install logs and CI/CD logs for the period when this package may have been installed to detect any suspicious activity
  • Review and rotate any credentials or secrets that may have been exposed on machines where this package was installed
  • Scan affected systems for signs of compromise or persistence mechanisms
  • Update dependency-cruiser to the latest version from the official npm registry to ensure legitimate dependencies are used

Sources

  1. GitHub Advisory GHSA-8r7w-6hqf-4x5p · GitHub Advisory Database

Cite this entry

"Malicious code in depcruise-wrap-stream-in-html (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 15, 2026; last updated August 15, 2026. https://supplychainattack.org/incident/malicious-code-in-depcruise-wrap-stream-in-html-npm-146my6

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in bazelisk (npm)

    A malicious npm package named bazelisk, impersonating Google's legitimate bazelbuild/bazelisk project, was published with a postinstall script that exfiltrates system and environment information to an attacker-controlled server. The package exhibits dependency-confusion and typosquatting characteristics, collecting hostname, platform, architecture, Node version, and npm lifecycle event data.

    npmCompromised packageDependency confusionTyposquatting
  2. resolvedcritical

    Malicious code in localize-extract (npm)

    localize-extract@1.0.0 on npm contained malicious postinstall code that exfiltrated host identifiers to an attacker-controlled endpoint. The package name resembled @angular/localize, suggesting a dependency-confusion or typosquatting attack.

    npmCompromised packageTyposquattingDependency confusion
  3. resolvedcritical

    Malicious code in gaarf-node-bq (npm)

    gaarf-node-bq is a malicious npm package that acts as a dependency-confusion/typosquat canary targeting Google's internal gaarf package. The package's postinstall script collects host metadata and exfiltrates it to an external endpoint without user consent.

    npmDependency confusionTyposquattingCompromised package
  4. resolvedcritical

    Malicious code in ngsw-config (npm)

    A malicious npm package named ngsw-config was published to shadow Angular's legitimate tooling. The package's postinstall script collected and exfiltrated host identifiers (hostname, platform, architecture, Node version, package/lifecycle name, timestamp) to a hardcoded endpoint without consent or documentation, targeting dependency-confusion scenarios in internal build systems.

    npmCompromised packageTyposquattingDependency confusion