VYPR

npm · Malicious package advisory

Malware

@citi-icg-158830/elemental-chameleon

MAL-2026-3806

Malicious code in @citi-icg-158830/elemental-chameleon (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (698e88fd9d64450847d476a41187198acc173deacf9c5484791a4fdb6fbbe969)
The package @citi-icg-158830/elemental-chameleon was found to contain malicious code.

## Source: ossf-package-analysis (584d2e027d86f89b78898d46a4aab1a0bd131897750c876c729e2247b1479a40)
The OpenSSF Package Analysis project identified '@citi-icg-158830/elemental-chameleon' @ 0.0.0-defensive-callback.1 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

Compromised versions (2)

  • 0.0.0-defensive-callback.1
  • 0.0.0-defensive-callback

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.