npm · Malicious package advisory
Malware@citi-icg-158830/elemental-chameleon
MAL-2026-3806
Malicious code in @citi-icg-158830/elemental-chameleon (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (698e88fd9d64450847d476a41187198acc173deacf9c5484791a4fdb6fbbe969) The package @citi-icg-158830/elemental-chameleon was found to contain malicious code. ## Source: ossf-package-analysis (584d2e027d86f89b78898d46a4aab1a0bd131897750c876c729e2247b1479a40) The OpenSSF Package Analysis project identified '@citi-icg-158830/elemental-chameleon' @ 0.0.0-defensive-callback.1 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
Compromised versions (2)
- 0.0.0-defensive-callback.1
- 0.0.0-defensive-callback
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.