@trackunit/iris-app-sdk-vite @1.2.10-alpha-d785aff3531.0
Vulnerability report · Last retrieved from osv.dev August 6, 2026 at 7:08 PM UTC
OSV ID
MAL-2026-13421
Ecosystem
npm
Summary
This version of @trackunit/iris-app-sdk-vite declares cross-keychain: ^1.1.0 in its package.json dependencies. cross-keychain is a package associated with the Shai-Hulud npm worm campaign, whose install-time lifecycle hooks harvest developer credentials (npm tokens, GitHub tokens, cloud credentials) and self-propagate by republishing tainted versions under the victim's identity. Running npm install against this @trackunit/iris-app-sdk-vite version resolves and executes cross-keychain's install scripts on the installer's machine. The version string ( 1.2.10-alpha-d785aff3531.0 ) also matches the anomalous alpha-tag pattern seen across other tainted @trackunit/* releases published during the Shai-Hulud incident window, and does not correspond to a legitimate maintainer release cadence.
Source: amazon-inspector (22e0a86ea25c65d4c79c952852d254c96966dbc20a2c1017ea29cde939c35b5c)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.