Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in @trackunit/iris-app-sdk-vite (npm)

Malicious code was published in @trackunit/iris-app-sdk-vite (npm) version 1.2.10-alpha-d785aff3531.0, which declares a dependency on cross-keychain—a package associated with the Shai-Hulud npm worm campaign. Installation of this version executes malicious install-time scripts that harvest developer credentials and self-propagate the worm.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Developers installing @trackunit/iris-app-sdk-vite version 1.2.10-alpha-d785aff3531.0 and any downstream projects depending on this package.
Ecosystems
Attack vectors
Threat actor
Affected entities
  • @trackunit/iris-app-sdk-vite · 1.2.10-alpha-d785aff3531.0
  • cross-keychain · ^1.1.0Malicious dependency injected into @trackunit/iris-app-sdk-vite

The npm package @trackunit/iris-app-sdk-vite version 1.2.10-alpha-d785aff3531.0 contains malicious code through a dependency on cross-keychain (^1.1.0), a package linked to the Shai-Hulud npm worm campaign. When developers run npm install against this version, the cross-keychain install-time lifecycle hooks are executed on their machines.\n\nThe malicious scripts harvest sensitive developer credentials including npm tokens, GitHub tokens, and cloud credentials. The worm then self-propagates by republishing tainted versions under the victim's identity, enabling further compromise of the npm ecosystem.\n\nThe anomalous version string (1.2.10-alpha-d785aff3531.0) matches patterns observed in other compromised @trackunit/* releases during the Shai-Hulud incident window and does not align with legitimate maintainer release practices, indicating account compromise or package takeover.\n\nThis incident was identified and credited to the OpenSSF's malicious-packages repository.

Indicators of compromise

Packages
  • @trackunit/iris-app-sdk-vite@1.2.10-alpha-d785aff3531.0
  • cross-keychain@^1.1.0

Remediation

  • Immediately remove @trackunit/iris-app-sdk-vite version 1.2.10-alpha-d785aff3531.0 from your project dependencies.
  • Audit npm tokens, GitHub tokens, and cloud credentials for any unauthorized access or activity if this version was installed.
  • Rotate all developer credentials (npm tokens, GitHub tokens, AWS keys, etc.) that may have been exposed.
  • Review npm publish history and git commit logs for unauthorized changes or releases.
  • Update to a known-safe version of @trackunit/iris-app-sdk-vite once the maintainers have secured their account and released a patched version.
  • Scan your codebase and build artifacts for signs of the Shai-Hulud worm or other malicious packages.
  • Monitor for any unauthorized package republications under your identity.

Sources

  1. GitHub Advisory GHSA-5hcf-5hp5-35c7 · GitHub Advisory Database

Cite this entry

"Malicious code in @trackunit/iris-app-sdk-vite (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 6, 2026; last updated August 7, 2026. https://supplychainattack.org/incident/malicious-code-in-trackunit-iris-app-sdk-vite-npm-1to0jx

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in pfp-forms-sme-loan (npm)

    The npm package pfp-forms-sme-loan contains malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under well1.site. Any system that imported this package should be considered compromised.

    npmCompromised packageMalicious commit
  2. resolvedcritical

    Malicious code in akamaijs-sensorv1 (npm)

    The npm package akamaijs-sensorv1, which advertises itself as an Akamai Bot Manager sensor generator, contains malicious code that executes hidden dynamic code and fetches remote instructions from a Google Calendar-based command-and-control channel. The package uses invisible Unicode characters to conceal executable code and establishes a covert remote-code execution sink controlled by an attacker-owned email account.

    npmCompromised packageMalicious commit
  3. containedcritical

    Malicious code in akamaijs-sensor (npm)

    The npm package akamaijs-sensor contained malicious code that executed arbitrary JavaScript via hidden Unicode-encoded bytes and established a command-and-control channel through a Google Calendar dead-drop. The package was designed to run attacker-authored code in the consumer's Node process when the sensor() API was called.

    npmCompromised packageMalicious commit
  4. resolvedcritical

    Malicious code in @velliajs/discord (npm)

    @velliajs/discord, a malicious npm package masquerading as a discord.js clone, contained two hostile mechanisms: an unpinned private git dependency with embedded GitHub PAT enabling arbitrary code injection on install, and a hidden runtime kill-switch that gates bot functionality based on a remote allow-list. Two live GitHub Personal Access Tokens were hardcoded in the package.

    npmCompromised packageMalicious commit