Malicious code in anthropic-shared-logger (npm)
The npm package 'anthropic-shared-logger' version 8.0.5 is a malicious package impersonating Anthropic's internal namespace. It contains a postinstall script that executes shell commands on the installer's machine and exfiltrates system information and environment variables to an attacker-controlled server. This behavior is characteristic of a dependency confusion attack, potentially exposing sensitive host data during build processes that mistakenly resolve this package from the public registry.
AI Analysis
Technical Summary
The 'anthropic-shared-logger' npm package version 8.0.5 impersonates Anthropic's internal namespace and includes a postinstall hook that runs on every 'npm install'. This hook fetches the installer's public IP from api.ipify.org, executes shell commands ('id' or 'ver', 'whoami', 'hostname') via child_process.exec, and sends the hostname, current working directory, USERDOMAIN/COMPANY environment variables, IP address, and command output to a hardcoded Interactsh out-of-band endpoint over plain HTTP. This setup enables host reconnaissance and data exfiltration, consistent with a Birsan-style dependency confusion attack. Any build system that resolves this package from the public npm registry leaks identity and host data to the attacker, enabling potential targeted follow-on compromise.
Potential Impact
Systems that install the malicious 'anthropic-shared-logger' package version 8.0.5 will execute arbitrary shell commands during installation, leading to exposure of sensitive host information including environment variables, hostname, user identity, and public IP address. This data is exfiltrated to an attacker-controlled server, which can facilitate targeted attacks or further compromise. The attack leverages dependency confusion, affecting build systems that mistakenly resolve this package from the public npm registry instead of an internal source.
Mitigation Recommendations
No official patch or remediation is currently documented. Users and organizations should verify the source of the 'anthropic-shared-logger' package before installation to ensure it is not resolved from the public npm registry. Implement strict package resolution policies to prevent dependency confusion attacks, such as using scoped packages, private registries, or package allowlists. Monitor build configurations to avoid unintentional public package resolution. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.
Malicious code in anthropic-shared-logger (npm)
Description
The npm package 'anthropic-shared-logger' version 8.0.5 is a malicious package impersonating Anthropic's internal namespace. It contains a postinstall script that executes shell commands on the installer's machine and exfiltrates system information and environment variables to an attacker-controlled server. This behavior is characteristic of a dependency confusion attack, potentially exposing sensitive host data during build processes that mistakenly resolve this package from the public registry.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'anthropic-shared-logger' npm package version 8.0.5 impersonates Anthropic's internal namespace and includes a postinstall hook that runs on every 'npm install'. This hook fetches the installer's public IP from api.ipify.org, executes shell commands ('id' or 'ver', 'whoami', 'hostname') via child_process.exec, and sends the hostname, current working directory, USERDOMAIN/COMPANY environment variables, IP address, and command output to a hardcoded Interactsh out-of-band endpoint over plain HTTP. This setup enables host reconnaissance and data exfiltration, consistent with a Birsan-style dependency confusion attack. Any build system that resolves this package from the public npm registry leaks identity and host data to the attacker, enabling potential targeted follow-on compromise.
Potential Impact
Systems that install the malicious 'anthropic-shared-logger' package version 8.0.5 will execute arbitrary shell commands during installation, leading to exposure of sensitive host information including environment variables, hostname, user identity, and public IP address. This data is exfiltrated to an attacker-controlled server, which can facilitate targeted attacks or further compromise. The attack leverages dependency confusion, affecting build systems that mistakenly resolve this package from the public npm registry instead of an internal source.
Mitigation Recommendations
No official patch or remediation is currently documented. Users and organizations should verify the source of the 'anthropic-shared-logger' package before installation to ensure it is not resolved from the public npm registry. Implement strict package resolution policies to prevent dependency confusion attacks, such as using scoped packages, private registries, or package allowlists. Monitor build configurations to avoid unintentional public package resolution. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-4479
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-4vj8-cm74-gcx3"]
- Ecosystems
- ["npm"]
Threat ID: 6a96f31aacd9273b49e497b5
Added to database: 09/01/2026, 15:45:30 UTC
Last enriched: 09/08/2026, 08:23:12 UTC
Last updated: 09/08/2026, 08:23:12 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.