Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

@apicity/metanpm

@apicity/meta is a confirmed malicious npm package (MAL-2026-13412) that executes malicious code on install (malicious versions 0.8.0, 0.8.1, 0.8.2…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in @apicity/meta (npm)

MAL-2026-13412
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @apicity/meta

What this malware does

dist/src/example.js at line 12 contains a reference to litter.catbox.moe, an anonymous mutable file-hosting service used as a second-stage payload host in the TanStack/Shai-Hulud npm supply-chain compromise campaign. Anonymous ephemeral file hosts have no legitimate role in a published npm package's runtime code; their appearance matches the known-bad-infrastructure-dropper fingerprint where installer-side code fetches and executes attacker-controlled bytes from a host that cannot be pinned or verified. The package is scoped and shipped as a distributable, so consumers installing or loading @apicity/meta are exposed to whatever content is served from that host at the moment the reference is resolved.

Malicious versions

7 flagged
0.8.00.8.10.8.20.8.30.8.40.8.50.8.6

Indicators of compromise (SHA-256)

131cbb214b98f8307745eff526b3f512ac27dc6743a2873b3fb2fdd9b6e701d0
19edd2e49211988ff76221e8fae2f54ea48ecce93f53111d6a4b3f178f670fb8
348fc3474cf19bb88ef64fc7990865145cc84c86664c18b08b47b3f6cf7da76a
9e3b6925f0e0152943fd0e6b4950113ce42c0ab48dd0d643ad60606ae9785c52
a748f9ca8e1731ba7c7c2d3a2f7643fd290f090fc118e65a8cec086cc8d51583
c76d2a899fc3db1427439c97acc4a873277804f6c771d524a3b93b70ff533581
df97618d24d1223f42ce4837e8ad5df36e7ea97d458c54fdf1a242d72423e8d9

Detection & response playbook

Malicious package
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for @apicity/meta (7 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging @apicity/meta across your stack and pipelines.

  2. If you installed it — respond

    Remove @apicity/meta from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If @apicity/meta was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks @apicity/meta before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. @apicity/meta on npm has been identified as a malicious package (versions 0.8.0, 0.8.1, 0.8.2, 0.8.3, 0.8.4, 0.8.5, 0.8.6 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-016362IN-MAL-2026-016482IN-MAL-2026-016480IN-MAL-2026-016486IN-MAL-2026-016476IN-MAL-2026-016481IN-MAL-2026-016483

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks @apicity/meta-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

@apicity/meta (npm) malicious package — MAL-2026-13412 | O3 Security