MAL-2026-13421
Malicious code in @trackunit/iris-app-sdk-vite (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (22e0a86ea25c65d4c79c952852d254c96966dbc20a2c1017ea29cde939c35b5c) This version of @trackunit/iris-app-sdk-vite declares `cross-keychain: ^1.1.0` in its package.json dependencies. cross-keychain is a package associated with the Shai-Hulud npm worm campaign, whose install-time lifecycle hooks harvest developer credentials (npm tokens, GitHub tokens, cloud credentials) and self-propagate by republishing tainted versions under the victim's identity. Running `npm install` against this @trackunit/iris-app-sdk-vite version resolves and executes cross-keychain's install scripts on the installer's machine. The version string (`1.2.10-alpha-d785aff3531.0`) also matches the anomalous alpha-tag pattern seen across other tainted @trackunit/* releases published during the Shai-Hulud incident window, and does not correspond to a legitimate maintainer release cadence.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for @trackunit/iris-app-sdk-vite (npm). Pin to a known-safe version or switch to an alternative.