Malicious code in @citi-icg-158830/elemental-chameleon (npm)
The npm package @citi-icg-158830/elemental-chameleon version 0.0.0-defensive-callback.1 was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on adoption of the malicious version
- Ecosystems
- Attack vectors
- Affected entities
- @citi-icg-158830/elemental-chameleon · 0.0.0-defensive-callback.1
The npm package @citi-icg-158830/elemental-chameleon was flagged as containing malicious code by multiple security sources. Amazon Inspector and the OpenSSF Package Analysis project independently identified the package as malicious, specifically version 0.0.0-defensive-callback.1.
According to the OpenSSF analysis, the malicious behavior involves communication with a domain associated with malicious activity. The package was cataloged in the OpenSSF malicious packages repository (MAL-2026-3806).
The advisory was published on 2026-07-27 via GitHub Security Advisory GHSA-3x32-552f-fg4j. The package appears to be contained as it has been identified and flagged in public security databases.
Indicators of compromise
- Packages
- @citi-icg-158830/elemental-chameleon@0.0.0-defensive-callback.1
Remediation
- Remove @citi-icg-158830/elemental-chameleon from all projects immediately
- Audit project dependencies to ensure no versions of this package are installed
- Review any systems that may have executed code from this package for signs of compromise
- Monitor for suspicious network activity or data exfiltration from affected systems
- Update to a safe alternative package if functionality is required
Sources
- GitHub Advisory GHSA-3x32-552f-fg4j · GitHub Advisory Database
Cite this entry
"Malicious code in @citi-icg-158830/elemental-chameleon (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 27, 2026; last updated July 28, 2026. https://supplychainattack.org/incident/malicious-code-in-citi-icg-158830-elemental-chameleon-npm-e9xtse
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
Malware in @vaultflow/create-flow
Malware discovered in the npm package @vaultflow/create-flow. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @vaultflow/update-flow
Malware was discovered in the npm package @vaultflow/update-flow. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - resolvedcritical
Malicious code in tempo-components (npm)
The npm package tempo-components contained malicious code (poc.js) that collected host metadata and identity information and exfiltrated it to an external endpoint. The package performed system reconnaissance by capturing hostname, platform, and user identity before transmitting the data via HTTPS.
npmCompromised package - containedcritical
Malicious code in @antv/g-webgl-compute (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-webgl-compute, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit