MAL-2026-13412
Dashboard / Malicious Package / MAL-2026-13412
MAL-2026-13412
Summary: Malicious code in @apicity/meta (npm)
Details: Source: amazon-inspector (c76d2a899fc3db1427439c97acc4a873277804f6c771d524a3b93b70ff533581) dist/src/example.js at line 12 contains a reference to litter.catbox.moe, an anonymous mutable file-hosting service used as a second-stage payload host in the TanStack/Shai-Hulud npm supply-chain compromise campaign. Anonymous ephemeral file hosts have no legitimate role in a published npm package's runtime code; their appearance matches the known-bad-infrastructure-dropper fingerprint where installer-side code fetches and executes attacker-controlled bytes from a host that cannot be pinned or verified. The package is scoped and shipped as a distributable, so consumers installing or loading @apicity/meta are exposed to whatever content is served from that host at the moment the reference is resolved.
References: https://www.npmjs.com/package/@apicity/meta/v/0.8.5, https://www.npmjs.com/package/@apicity/meta/v/0.8.2, https://www.npmjs.com/package/@apicity/meta/v/0.8.1, https://www.npmjs.com/package/@apicity/meta/v/0.8.3, https://www.npmjs.com/package/@apicity/meta/v/0.8.0, https://www.npmjs.com/package/@apicity/meta/v/0.8.6, https://www.npmjs.com/package/@apicity/meta/v/0.8.4, https://www.npmjs.com/package/@apicity/meta/v/0.8.8
Affected packages
Package
Name: @apicity/meta
Purl: pkg:npm/%40apicity/meta
Affected ranges
Type: N/A
Events:
