Malicious code in @trackunit/iris-app-sdk-vite (npm)
Malicious code was published in @trackunit/iris-app-sdk-vite (npm) version 1.2.10-alpha-d785aff3531.0, which declares a dependency on cross-keychain—a package associated with the Shai-Hulud npm worm campaign. Installation of this version executes malicious install-time scripts that harvest developer credentials and self-propagate the worm.
- Disclosed
- Last updated
- Blast radius
- Developers installing @trackunit/iris-app-sdk-vite version 1.2.10-alpha-d785aff3531.0 and any downstream projects depending on this package.
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- @trackunit/iris-app-sdk-vite · 1.2.10-alpha-d785aff3531.0
- cross-keychain · ^1.1.0Malicious dependency injected into @trackunit/iris-app-sdk-vite
The npm package @trackunit/iris-app-sdk-vite version 1.2.10-alpha-d785aff3531.0 contains malicious code through a dependency on cross-keychain (^1.1.0), a package linked to the Shai-Hulud npm worm campaign. When developers run npm install against this version, the cross-keychain install-time lifecycle hooks are executed on their machines.\n\nThe malicious scripts harvest sensitive developer credentials including npm tokens, GitHub tokens, and cloud credentials. The worm then self-propagates by republishing tainted versions under the victim's identity, enabling further compromise of the npm ecosystem.\n\nThe anomalous version string (1.2.10-alpha-d785aff3531.0) matches patterns observed in other compromised @trackunit/* releases during the Shai-Hulud incident window and does not align with legitimate maintainer release practices, indicating account compromise or package takeover.\n\nThis incident was identified and credited to the OpenSSF's malicious-packages repository.
Indicators of compromise
- Packages
- @trackunit/iris-app-sdk-vite@1.2.10-alpha-d785aff3531.0
- cross-keychain@^1.1.0
Remediation
- Immediately remove @trackunit/iris-app-sdk-vite version 1.2.10-alpha-d785aff3531.0 from your project dependencies.
- Audit npm tokens, GitHub tokens, and cloud credentials for any unauthorized access or activity if this version was installed.
- Rotate all developer credentials (npm tokens, GitHub tokens, AWS keys, etc.) that may have been exposed.
- Review npm publish history and git commit logs for unauthorized changes or releases.
- Update to a known-safe version of @trackunit/iris-app-sdk-vite once the maintainers have secured their account and released a patched version.
- Scan your codebase and build artifacts for signs of the Shai-Hulud worm or other malicious packages.
- Monitor for any unauthorized package republications under your identity.
Sources
- GitHub Advisory GHSA-5hcf-5hp5-35c7 · GitHub Advisory Database
Cite this entry
"Malicious code in @trackunit/iris-app-sdk-vite (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 6, 2026; last updated August 7, 2026. https://supplychainattack.org/incident/malicious-code-in-trackunit-iris-app-sdk-vite-npm-1to0jx
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in pfp-forms-sme-loan (npm)
The npm package pfp-forms-sme-loan contains malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under well1.site. Any system that imported this package should be considered compromised.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in akamaijs-sensorv1 (npm)
The npm package akamaijs-sensorv1, which advertises itself as an Akamai Bot Manager sensor generator, contains malicious code that executes hidden dynamic code and fetches remote instructions from a Google Calendar-based command-and-control channel. The package uses invisible Unicode characters to conceal executable code and establishes a covert remote-code execution sink controlled by an attacker-owned email account.
npmCompromised packageMalicious commit - containedcritical
Malicious code in akamaijs-sensor (npm)
The npm package akamaijs-sensor contained malicious code that executed arbitrary JavaScript via hidden Unicode-encoded bytes and established a command-and-control channel through a Google Calendar dead-drop. The package was designed to run attacker-authored code in the consumer's Node process when the sensor() API was called.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in @velliajs/discord (npm)
@velliajs/discord, a malicious npm package masquerading as a discord.js clone, contained two hostile mechanisms: an unpinned private git dependency with embedded GitHub PAT enabling arbitrary code injection on install, and a hidden runtime kill-switch that gates bot functionality based on a remote allow-list. Two live GitHub Personal Access Tokens were hardcoded in the package.
npmCompromised packageMalicious commit