OpenSSF/OSV advisory MAL-2026-13421 confirms this npm version as malicious. This version of @trackunit/iris-app-sdk-vite declares `cross-keychain: ^1.1.0` in its package.json dependencies. cross-keychain is a package associated with the Shai-Hulud npm worm campaign, whose install-time lifecycle hooks harvest developer credentials (npm tokens, GitHub tokens, cloud credentials) and self-propagate by republishing tainted versions under the victim's identity...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in @trackunit/iris-app-sdk-vite (npm)
Details
This version of @trackunit/iris-app-sdk-vite declares `cross-keychain: ^1.1.0` in its package.json dependencies. cross-keychain is a package associated with the Shai-Hulud npm worm campaign, whose install-time lifecycle hooks harvest developer credentials (npm tokens, GitHub tokens, cloud credentials) and self-propagate by republishing tainted versions under the victim's identity. Running `npm install` against this @trackunit/iris-app-sdk-vite version resolves and executes cross-keychain's install scripts on the installer's machine. The version string (`1.2.10-alpha-d785aff3531.0`) also matches the anomalous alpha-tag pattern seen across other tainted @trackunit/* releases published during the Shai-Hulud incident window, and does not correspond to a legitimate maintainer release cadence.
Decision reason
OpenSSF Malicious Packages via OSV confirms @trackunit/iris-app-sdk-vite@1.2.10-alpha-d785aff3531.0 as malicious (MAL-2026-13421): Malicious code in @trackunit/iris-app-sdk-vite (npm)