Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in @tc-core/campus-service (npm)

The npm package @tc-core/campus-service version 0.0.0-defensive-callback was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; depends on adoption of affected version
Ecosystems
Attack vectors
Affected entities
  • @tc-core/campus-service · 0.0.0-defensive-callback

The npm package @tc-core/campus-service was flagged as containing malicious code by multiple security sources. Amazon Inspector identified the malicious package via hash analysis (c58f691cfdb7301c271067776e2e3bc260d4cbb8880345d03e840729d849b580), and the OpenSSF Package Analysis project independently confirmed the finding for version 0.0.0-defensive-callback.\n\nThe malicious behavior was attributed to the package communicating with a domain associated with malicious activity. The advisory was published on 2026-07-27 and credited to the OpenSSF malicious-packages repository.\n\nThe package appears to be contained as it has been identified and flagged in public security advisories, allowing users to detect and remove it.

Indicators of compromise

Packages
  • @tc-core/campus-service@0.0.0-defensive-callback
Hashes
  • c58f691cfdb7301c271067776e2e3bc260d4cbb8880345d03e840729d849b580
  • 9bbf1badd9e8d2be29855017cbd2d690f33885c0884c653412d7d4e463656494

Remediation

  • Remove @tc-core/campus-service from all projects, particularly version 0.0.0-defensive-callback
  • Audit project dependencies to identify any installations of this package
  • Review any network activity or data exfiltration that may have occurred while the package was installed
  • Use npm audit or similar tools to detect the presence of this malicious package
  • Consider rotating any credentials or secrets that may have been exposed

Sources

  1. GitHub Advisory GHSA-3hvw-w2fc-p2fg · GitHub Advisory Database

Cite this entry

"Malicious code in @tc-core/campus-service (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 27, 2026; last updated July 28, 2026. https://supplychainattack.org/incident/malicious-code-in-tc-core-campus-service-npm-c84td4

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. activecritical

    Malware in @vaultflow/create-flow

    Malware discovered in the npm package @vaultflow/create-flow. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2. activecritical

    Malware in @vaultflow/update-flow

    Malware was discovered in the npm package @vaultflow/update-flow. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  3. resolvedcritical

    Malicious code in tempo-components (npm)

    The npm package tempo-components contained malicious code (poc.js) that collected host metadata and identity information and exfiltrated it to an external endpoint. The package performed system reconnaissance by capturing hostname, platform, and user identity before transmitting the data via HTTPS.

    npmCompromised package
  4. containedcritical

    Malicious code in @antv/g-webgl-compute (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-webgl-compute, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit