{"id":"MAL-2026-13412","summary":"Malicious code in @apicity/meta (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c76d2a899fc3db1427439c97acc4a873277804f6c771d524a3b93b70ff533581)\ndist/src/example.js at line 12 contains a reference to litter.catbox.moe, an anonymous mutable file-hosting service used as a second-stage payload host in the TanStack/Shai-Hulud npm supply-chain compromise campaign. Anonymous ephemeral file hosts have no legitimate role in a published npm package's runtime code; their appearance matches the known-bad-infrastructure-dropper fingerprint where installer-side code fetches and executes attacker-controlled bytes from a host that cannot be pinned or verified. The package is scoped and shipped as a distributable, so consumers installing or loading @apicity/meta are exposed to whatever content is served from that host at the moment the reference is resolved.\n","modified":"2026-08-07T13:20:09.878268840Z","published":"2026-08-06T13:10:14Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-06T14:19:45.21950783Z","modified_time":"2026-08-06T13:10:14Z","sha256":"131cbb214b98f8307745eff526b3f512ac27dc6743a2873b3fb2fdd9b6e701d0","source":"amazon-inspector","versions":["0.8.5"],"id":"IN-MAL-2026-016362"},{"import_time":"2026-08-06T14:19:51.623279442Z","modified_time":"2026-08-06T13:38:53Z","sha256":"19edd2e49211988ff76221e8fae2f54ea48ecce93f53111d6a4b3f178f670fb8","source":"amazon-inspector","versions":["0.8.2"],"id":"IN-MAL-2026-016482"},{"id":"IN-MAL-2026-016480","import_time":"2026-08-06T14:19:51.553867071Z","modified_time":"2026-08-06T13:38:36Z","sha256":"348fc3474cf19bb88ef64fc7990865145cc84c86664c18b08b47b3f6cf7da76a","source":"amazon-inspector","versions":["0.8.1"]},{"sha256":"9e3b6925f0e0152943fd0e6b4950113ce42c0ab48dd0d643ad60606ae9785c52","source":"amazon-inspector","versions":["0.8.3"],"id":"IN-MAL-2026-016486","import_time":"2026-08-06T14:19:51.836133704Z","modified_time":"2026-08-06T13:39:27Z"},{"source":"amazon-inspector","versions":["0.8.0"],"id":"IN-MAL-2026-016476","import_time":"2026-08-06T14:19:51.356413815Z","modified_time":"2026-08-06T13:38:01Z","sha256":"a748f9ca8e1731ba7c7c2d3a2f7643fd290f090fc118e65a8cec086cc8d51583"},{"id":"IN-MAL-2026-016481","import_time":"2026-08-06T14:19:51.587152418Z","modified_time":"2026-08-06T13:38:46Z","sha256":"c76d2a899fc3db1427439c97acc4a873277804f6c771d524a3b93b70ff533581","source":"amazon-inspector","versions":["0.8.6"]},{"id":"IN-MAL-2026-016483","import_time":"2026-08-06T14:19:51.702221412Z","modified_time":"2026-08-06T13:39:03Z","sha256":"df97618d24d1223f42ce4837e8ad5df36e7ea97d458c54fdf1a242d72423e8d9","source":"amazon-inspector","versions":["0.8.4"]},{"id":"IN-MAL-2026-017062","import_time":"2026-08-07T12:51:24.562669055Z","modified_time":"2026-08-07T12:40:21Z","sha256":"c0c9f65af9eff5ef8d307d7a9c462525cb4be16da773d1157ba74008f62e7893","source":"amazon-inspector","versions":["0.8.8"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@apicity/meta/v/0.8.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@apicity/meta/v/0.8.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@apicity/meta/v/0.8.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@apicity/meta/v/0.8.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@apicity/meta/v/0.8.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@apicity/meta/v/0.8.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@apicity/meta/v/0.8.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@apicity/meta/v/0.8.8"}],"affected":[{"package":{"name":"@apicity/meta","ecosystem":"npm","purl":"pkg:npm/%40apicity/meta"},"versions":["0.8.5","0.8.2","0.8.1","0.8.3","0.8.0","0.8.6","0.8.4","0.8.8"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@apicity/meta/MAL-2026-13412.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"tlsh":"0271e19599f34026066b94bc568f5416e279d4073048ed0c3f8dc3acaf5a87d4ba3bde","path":"dist/src/example.js","sha256":"21c7721228ffa5c5bc685cab4fd6bc421971390f236bcf0fdd0662b9a8598f00"}],"package_integrity":[{"filename":"meta-0.8.5.tgz","hashes":{"sha1":"cb142b17e43b8d3055aa532d5f9b2554fa30f43c","sha512_sri":"sha512-hhdIDoJa9K1goWFXxHTKDJwE7ZqdTMrP83pUnyde44YT/4/OlutsbeP4Z67lPjrQiIuU6UzmsmKxssLU8S7f5A=="}}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}