MAL-2026-13412

    Dashboard / Malicious Package / MAL-2026-13412

    MAL-2026-13412

    Published: 6 Aug 2026Last Modified: 7 Aug 2026

    Summary: Malicious code in @apicity/meta (npm)

    Details: Source: amazon-inspector (c76d2a899fc3db1427439c97acc4a873277804f6c771d524a3b93b70ff533581) dist/src/example.js at line 12 contains a reference to litter.catbox.moe, an anonymous mutable file-hosting service used as a second-stage payload host in the TanStack/Shai-Hulud npm supply-chain compromise campaign. Anonymous ephemeral file hosts have no legitimate role in a published npm package's runtime code; their appearance matches the known-bad-infrastructure-dropper fingerprint where installer-side code fetches and executes attacker-controlled bytes from a host that cannot be pinned or verified. The package is scoped and shipped as a distributable, so consumers installing or loading @apicity/meta are exposed to whatever content is served from that host at the moment the reference is resolved.

    Affected packages

    Package

    Name: @apicity/meta

    Purl: pkg:npm/%40apicity/meta

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.8.5
    0.8.2
    0.8.1
    0.8.3
    0.8.0
    0.8.6
    0.8.4
    0.8.8
    MAL-2026-13412 | CVE-DB