Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in sams-sr-sdk-h5 (npm)

0
Critical
Published: 07/06/2026 (07/06/2026, 00:00:00 UTC)
Source: GCVE Database
Product: sams-sr-sdk-h5

Description

The sams-sr-sdk-h5 npm package is a malicious package published to perform dependency confusion attacks by impersonating an internal package namespace. It includes a preinstall script that executes automatically during npm install, collecting host metadata including public IP, hostname, OS username, and runtime environment, then sends this data to an attacker-controlled Sentry project. The package also silently routes application error telemetry and end-user PII to the attacker's Sentry endpoint if used as intended. This behavior constitutes reconnaissance and data exfiltration. The affected version is 7.0.0. There is no official patch or remediation guidance provided.

Affected software

npmghsa
sams-sr-sdk-h5
Affected versions
=7.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/14/2026, 09:37:27 UTC

Technical Analysis

The sams-sr-sdk-h5 package was published to the npm registry by an attacker as part of a dependency confusion campaign targeting organizations using an internal 'sams' namespace. The package declares a preinstall hook that runs automatically upon installation, which executes a script that collects the installing host's public IP address and other personally identifiable information (PII) such as hostname, OS username, and runtime metadata. This information is sent to a hardcoded attacker-controlled Sentry DSN with sendDefaultPii enabled. Additionally, the package's initialization silently forwards application errors and PII to the attacker's Sentry project if no DSN is supplied by the user, further compromising privacy and security. The package name and minimal README are crafted to mimic legitimate internal packages, increasing the likelihood of accidental installation. The malicious payload is identical across packages published by this attacker, differing only in package name and target Sentry project. The affected version is exactly 7.0.0. No patch or official fix is currently documented.

Potential Impact

Installing this package results in automatic exfiltration of sensitive host metadata including public IP address, hostname, OS username, and runtime environment details to an attacker-controlled Sentry project. Additionally, any application errors and end-user PII may be silently sent to the attacker if the package is used without specifying a different Sentry DSN. This compromises confidentiality and privacy of the host and potentially end users. The presence of this package on a system indicates a high likelihood of compromise, and all secrets and keys on the affected system should be considered exposed and rotated. The package enables attacker reconnaissance and data leakage without user interaction beyond installation.

Mitigation Recommendations

No official patch or remediation is currently available. Users should immediately remove the sams-sr-sdk-h5 package version 7.0.0 if installed. Because the package executes code at install time that exfiltrates sensitive data, any system with this package installed should be considered fully compromised. It is strongly recommended to rotate all secrets and keys stored on the affected system from a separate, trusted environment. Avoid installing packages from untrusted or unknown sources, especially those mimicking internal namespaces. Monitor for and block suspicious packages in your supply chain. Check vendor advisories or trusted security sources for updates on remediation or detection tools.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10233
Osv Schema Version
1.7.4
Aliases
["GHSA-3r2r-29px-gqp6"]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a55ff7168715ace432f230a

Added to database: 07/14/2026, 09:20:49 UTC

Last enriched: 07/14/2026, 09:37:27 UTC

Last updated: 07/24/2026, 18:22:55 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses