Malicious code in @logdna-web/styles (npm)
The @logdna-web/styles npm package is a malicious package published under a namespace mimicking a legitimate internal package scope. It contains a preinstall script that executes automatically during npm install, which collects the host's public IP and other personal identifiable information (PII) and sends it to an attacker-controlled Sentry project. The package also silently routes error reporting data from consumers to the attacker's Sentry endpoint if used without explicit configuration. This behavior is part of a dependency confusion reconnaissance campaign targeting developers searching for LogDNA packages.
AI Analysis
Technical Summary
The @logdna-web/styles package was published by an attacker impersonating the LogDNA namespace to exploit dependency confusion. It includes a preinstall hook that installs @sentry/node and runs a script to collect the installing machine's public IP (via Cloudflare's trace endpoint) and other PII, then deliberately triggers an exception to send this data to a hardcoded attacker-controlled Sentry DSN. Additionally, the package's init() function silently forwards error reports and user context to the attacker's Sentry project if no explicit DSN is provided, enabling ongoing data exfiltration. This campaign uses distinct Sentry project IDs per impersonated namespace to track successful installs per victim organization. The package version 0.8.40 is affected.
Potential Impact
Installation of this package results in exfiltration of the host machine's public IP address, hostname, OS username, and runtime environment metadata to an attacker-controlled Sentry project without user consent or disclosure. The preinstall script runs automatically during npm install, potentially before any application code, enabling early reconnaissance. Additionally, any use of the package's init() function without explicit configuration causes silent routing of error and user data to the attacker. This compromises confidentiality and privacy of the affected systems and may facilitate further targeted attacks. The package is considered fully compromising to any system where it is installed or running.
Mitigation Recommendations
No official patch or remediation is currently available. Users should immediately remove the @logdna-web/styles package version 0.8.40 from their projects. Rotate all secrets and keys stored on affected machines from a separate, uncompromised device. Review and audit dependency configurations to prevent dependency confusion attacks, including verifying package scopes and sources. Avoid installing packages from untrusted or suspicious namespaces. Monitor for any unauthorized network activity related to Sentry endpoints controlled by unknown parties. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Malicious code in @logdna-web/styles (npm)
Description
The @logdna-web/styles npm package is a malicious package published under a namespace mimicking a legitimate internal package scope. It contains a preinstall script that executes automatically during npm install, which collects the host's public IP and other personal identifiable information (PII) and sends it to an attacker-controlled Sentry project. The package also silently routes error reporting data from consumers to the attacker's Sentry endpoint if used without explicit configuration. This behavior is part of a dependency confusion reconnaissance campaign targeting developers searching for LogDNA packages.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The @logdna-web/styles package was published by an attacker impersonating the LogDNA namespace to exploit dependency confusion. It includes a preinstall hook that installs @sentry/node and runs a script to collect the installing machine's public IP (via Cloudflare's trace endpoint) and other PII, then deliberately triggers an exception to send this data to a hardcoded attacker-controlled Sentry DSN. Additionally, the package's init() function silently forwards error reports and user context to the attacker's Sentry project if no explicit DSN is provided, enabling ongoing data exfiltration. This campaign uses distinct Sentry project IDs per impersonated namespace to track successful installs per victim organization. The package version 0.8.40 is affected.
Potential Impact
Installation of this package results in exfiltration of the host machine's public IP address, hostname, OS username, and runtime environment metadata to an attacker-controlled Sentry project without user consent or disclosure. The preinstall script runs automatically during npm install, potentially before any application code, enabling early reconnaissance. Additionally, any use of the package's init() function without explicit configuration causes silent routing of error and user data to the attacker. This compromises confidentiality and privacy of the affected systems and may facilitate further targeted attacks. The package is considered fully compromising to any system where it is installed or running.
Mitigation Recommendations
No official patch or remediation is currently available. Users should immediately remove the @logdna-web/styles package version 0.8.40 from their projects. Rotate all secrets and keys stored on affected machines from a separate, uncompromised device. Review and audit dependency configurations to prevent dependency confusion attacks, including verifying package scopes and sources. Avoid installing packages from untrusted or suspicious namespaces. Monitor for any unauthorized network activity related to Sentry endpoints controlled by unknown parties. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10226
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-qcrg-93h5-r265"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a55ff7768715ace432f2613
Added to database: 07/14/2026, 09:20:55 UTC
Last enriched: 07/14/2026, 09:38:44 UTC
Last updated: 07/30/2026, 06:02:21 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.