Malicious code in @flex-ng/filter-pipe (npm)
The @flex-ng/filter-pipe npm package version 1.1.0 is a malicious package published as part of a dependency confusion campaign. It executes a preinstall script that installs @sentry/node and runs a script to exfiltrate the installer's public IP address and host metadata to an attacker-controlled Sentry project. This data collection occurs silently during npm install without user consent or documentation. The package impersonates an internal namespace to trick misconfigured resolvers into installing it instead of the legitimate private package. Removal of the package does not guarantee full remediation as the system may be fully compromised.
AI Analysis
Technical Summary
The @flex-ng/filter-pipe package (version 1.1.0) was published to the npm registry by an attacker to conduct dependency confusion attacks. It uses a preinstall lifecycle hook to automatically run a script that installs the @sentry/node client and sends telemetry data including the public IP, hostname, OS username, and runtime metadata to an attacker-controlled Sentry DSN. This exfiltration is done by triggering a runtime exception that is captured and sent to the attacker's Sentry project. The package name mimics an internal organizational scope (@flex-ng) to increase the likelihood of installation in target environments with misconfigured package resolvers. The attack is reconnaissance-focused, allowing attribution of installs to specific organizations. The malicious payload is identical across packages published by this attacker, differing only in package name and Sentry project ID. The package is considered fully compromising to any system where it is installed.
Potential Impact
Installation of this package results in the automatic exfiltration of sensitive host telemetry and environment metadata to an attacker-controlled endpoint without user knowledge or consent. This includes the public IP address, hostname, OS username, and runtime environment details. The presence of this package indicates a successful dependency confusion attack, potentially exposing internal organizational information and enabling further targeted attacks. According to the GHSA malware advisory, any system with this package installed should be considered fully compromised, and all secrets and keys on the system should be rotated immediately. Removal of the package alone may not remove all malicious artifacts or backdoors.
Mitigation Recommendations
No official patch or fix is available for this malicious package. The recommended mitigation is to immediately remove the @flex-ng/filter-pipe package version 1.1.0 from all affected systems. Because the package executes code at install time that may fully compromise the system, all secrets and credentials stored on the affected systems should be rotated from a clean environment. Organizations should audit their package resolvers and dependency configurations to prevent dependency confusion attacks by ensuring private packages are resolved correctly and not overridden by public packages with similar names. Monitoring for suspicious packages published under organizational scopes and restricting package publishing permissions can help prevent similar attacks.
Malicious code in @flex-ng/filter-pipe (npm)
Description
The @flex-ng/filter-pipe npm package version 1.1.0 is a malicious package published as part of a dependency confusion campaign. It executes a preinstall script that installs @sentry/node and runs a script to exfiltrate the installer's public IP address and host metadata to an attacker-controlled Sentry project. This data collection occurs silently during npm install without user consent or documentation. The package impersonates an internal namespace to trick misconfigured resolvers into installing it instead of the legitimate private package. Removal of the package does not guarantee full remediation as the system may be fully compromised.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The @flex-ng/filter-pipe package (version 1.1.0) was published to the npm registry by an attacker to conduct dependency confusion attacks. It uses a preinstall lifecycle hook to automatically run a script that installs the @sentry/node client and sends telemetry data including the public IP, hostname, OS username, and runtime metadata to an attacker-controlled Sentry DSN. This exfiltration is done by triggering a runtime exception that is captured and sent to the attacker's Sentry project. The package name mimics an internal organizational scope (@flex-ng) to increase the likelihood of installation in target environments with misconfigured package resolvers. The attack is reconnaissance-focused, allowing attribution of installs to specific organizations. The malicious payload is identical across packages published by this attacker, differing only in package name and Sentry project ID. The package is considered fully compromising to any system where it is installed.
Potential Impact
Installation of this package results in the automatic exfiltration of sensitive host telemetry and environment metadata to an attacker-controlled endpoint without user knowledge or consent. This includes the public IP address, hostname, OS username, and runtime environment details. The presence of this package indicates a successful dependency confusion attack, potentially exposing internal organizational information and enabling further targeted attacks. According to the GHSA malware advisory, any system with this package installed should be considered fully compromised, and all secrets and keys on the system should be rotated immediately. Removal of the package alone may not remove all malicious artifacts or backdoors.
Mitigation Recommendations
No official patch or fix is available for this malicious package. The recommended mitigation is to immediately remove the @flex-ng/filter-pipe package version 1.1.0 from all affected systems. Because the package executes code at install time that may fully compromise the system, all secrets and credentials stored on the affected systems should be rotated from a clean environment. Organizations should audit their package resolvers and dependency configurations to prevent dependency confusion attacks by ensuring private packages are resolved correctly and not overridden by public packages with similar names. Monitoring for suspicious packages published under organizational scopes and restricting package publishing permissions can help prevent similar attacks.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10222
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-4wmg-pwv3-88v4"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a55ff7768715ace432f262d
Added to database: 07/14/2026, 09:20:55 UTC
Last enriched: 07/14/2026, 09:39:23 UTC
Last updated: 07/24/2026, 17:12:36 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.