Malicious code in @apicity/meta (npm)
The npm package @apicity/meta contained malicious code that references litter.catbox.moe, an anonymous file-hosting service used in the TanStack/Shai-Hulud supply-chain compromise campaign. The package's dist/src/example.js file at line 12 contains a reference to this second-stage payload host, exposing all consumers to arbitrary code execution.
- Disclosed
- Last updated
- Blast radius
- All consumers of @apicity/meta npm package
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- @apicity/metanpm package containing malicious code
The npm package @apicity/meta was found to contain malicious code as part of a broader supply-chain compromise campaign. The package's dist/src/example.js file at line 12 contains a reference to litter.catbox.moe, an anonymous mutable file-hosting service.
This infrastructure pattern matches the known-bad-infrastructure-dropper fingerprint used in the TanStack/Shai-Hulud npm supply-chain compromise campaign. The reference to an anonymous ephemeral file host has no legitimate role in published npm package runtime code and indicates installer-side code designed to fetch and execute attacker-controlled bytes from an unverifiable host.
Because the package is scoped and shipped as a distributable, all consumers installing or loading @apicity/meta are exposed to whatever content is served from that host at the moment the reference is resolved. This represents a critical runtime code execution risk.
The incident was identified and credited to the OpenSSF malicious-packages repository.
Indicators of compromise
- Packages
- @apicity/meta
- Domains
- litter.catbox.moe
Remediation
- Immediately uninstall @apicity/meta from all systems and projects
- Remove @apicity/meta from package.json and lock files
- Audit all systems where @apicity/meta was installed for signs of compromise or unauthorized activity
- Review npm audit logs for any suspicious activity related to this package
- Consider using npm's security tools to scan for other potentially compromised dependencies
- Monitor for any indicators of compromise from the litter.catbox.moe domain
Sources
- GitHub Advisory GHSA-rw5c-r24c-f9c7 · GitHub Advisory Database
Cite this entry
"Malicious code in @apicity/meta (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 6, 2026; last updated August 7, 2026. https://supplychainattack.org/incident/malicious-code-in-apicity-meta-npm-1t7mf7
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malware in sui-gql-core
Malware was discovered in the npm package sui-gql-core. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @junofficial/baileys
The npm package @junofficial/baileys contained malware that fully compromised any system with the package installed or running. The malicious package has been identified and removed from distribution.
npmCompromised package - containedcritical
Malware in a.poltoradnev-package-a
The npm package a.poltoradnev-package-a contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in sui-move-rpc
Malware was discovered in the npm package sui-move-rpc, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.
npmCompromised package