Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in @apicity/meta (npm)

The npm package @apicity/meta contained malicious code that references litter.catbox.moe, an anonymous file-hosting service used in the TanStack/Shai-Hulud supply-chain compromise campaign. The package's dist/src/example.js file at line 12 contains a reference to this second-stage payload host, exposing all consumers to arbitrary code execution.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
All consumers of @apicity/meta npm package
Ecosystems
Attack vectors
Threat actor
Affected entities
  • @apicity/metanpm package containing malicious code

The npm package @apicity/meta was found to contain malicious code as part of a broader supply-chain compromise campaign. The package's dist/src/example.js file at line 12 contains a reference to litter.catbox.moe, an anonymous mutable file-hosting service.

This infrastructure pattern matches the known-bad-infrastructure-dropper fingerprint used in the TanStack/Shai-Hulud npm supply-chain compromise campaign. The reference to an anonymous ephemeral file host has no legitimate role in published npm package runtime code and indicates installer-side code designed to fetch and execute attacker-controlled bytes from an unverifiable host.

Because the package is scoped and shipped as a distributable, all consumers installing or loading @apicity/meta are exposed to whatever content is served from that host at the moment the reference is resolved. This represents a critical runtime code execution risk.

The incident was identified and credited to the OpenSSF malicious-packages repository.

Indicators of compromise

Packages
  • @apicity/meta
Domains
  • litter.catbox.moe

Remediation

  • Immediately uninstall @apicity/meta from all systems and projects
  • Remove @apicity/meta from package.json and lock files
  • Audit all systems where @apicity/meta was installed for signs of compromise or unauthorized activity
  • Review npm audit logs for any suspicious activity related to this package
  • Consider using npm's security tools to scan for other potentially compromised dependencies
  • Monitor for any indicators of compromise from the litter.catbox.moe domain

Sources

  1. GitHub Advisory GHSA-rw5c-r24c-f9c7 · GitHub Advisory Database

Cite this entry

"Malicious code in @apicity/meta (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 6, 2026; last updated August 7, 2026. https://supplychainattack.org/incident/malicious-code-in-apicity-meta-npm-1t7mf7

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malware in sui-gql-core

    Malware was discovered in the npm package sui-gql-core. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2. containedcritical

    Malware in @junofficial/baileys

    The npm package @junofficial/baileys contained malware that fully compromised any system with the package installed or running. The malicious package has been identified and removed from distribution.

    npmCompromised package
  3. containedcritical

    Malware in a.poltoradnev-package-a

    The npm package a.poltoradnev-package-a contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  4. containedcritical

    Malware in sui-move-rpc

    Malware was discovered in the npm package sui-move-rpc, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package