OpenSSF/OSV advisory MAL-2026-13412 confirms this npm version as malicious. dist/src/example.js at line 12 contains a reference to litter.catbox.moe, an anonymous mutable file-hosting service used as a second-stage payload host in the TanStack/Shai-Hulud npm supply-chain compromise campaign...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in @apicity/meta (npm)
Details
dist/src/example.js at line 12 contains a reference to litter.catbox.moe, an anonymous mutable file-hosting service used as a second-stage payload host in the TanStack/Shai-Hulud npm supply-chain compromise campaign. Anonymous ephemeral file hosts have no legitimate role in a published npm package's runtime code; their appearance matches the known-bad-infrastructure-dropper fingerprint where installer-side code fetches and executes attacker-controlled bytes from a host that cannot be pinned or verified. The package is scoped and shipped as a distributable, so consumers installing or loading @apicity/meta are exposed to whatever content is served from that host at the moment the reference is resolved.
Decision reason
OpenSSF Malicious Packages via OSV confirms @apicity/meta@0.8.3 as malicious (MAL-2026-13412): Malicious code in @apicity/meta (npm)