Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in syft-acp-atoms (npm)

0
High
Published: 07/16/2026 (07/16/2026, 00:00:00 UTC)
Source: GCVE Database
Product: syft-acp-atoms

Description

The syft-acp-atoms package published on npm is a malicious package designed for dependency confusion attacks. It mimics an internal package name to trick misconfigured resolvers into installing it instead of the intended private package. Upon installation, it executes a preinstall hook that collects host telemetry including hostname, OS username, and public IP, then sends this data to an attacker-controlled Sentry endpoint. This behavior is consistent with reconnaissance activity to identify successful installs in targeted organizations. The package contains no legitimate library code and solely functions to beacon telemetry data to the attacker.

Affected software

npmghsa
syft-acp-atoms
Affected versions
>=0.0.1-0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/07/2026, 00:29:56 UTC

Technical Analysis

The syft-acp-atoms npm package is part of a dependency confusion reconnaissance campaign. It impersonates an internal package name to be installed mistakenly by misconfigured package resolvers. The package declares a preinstall hook that runs automatically during npm install, which initializes a Sentry client with a hardcoded attacker-controlled DSN and collects telemetry data such as hostname, OS username, runtime metadata, and the public egress IP address. This data is sent to the attacker's Sentry project, allowing attribution of successful installs to specific victim organizations. The package also runs a beacon script that transmits hex-encoded host information to a malicious external URL. The package contains no functional library code, indicating its sole purpose is reconnaissance via telemetry exfiltration.

Potential Impact

Successful installation of this package results in the exfiltration of sensitive host telemetry including hostname, OS username, current working directory, runtime environment metadata, and public IP address to an attacker-controlled Sentry endpoint and an external URL. This information can be used by attackers to identify and profile victim environments, facilitating further targeted attacks. The package does not provide any legitimate functionality and solely acts as a reconnaissance beacon. There is no indication of direct code execution beyond the telemetry collection and exfiltration during installation.

Mitigation Recommendations

Avoid installing packages from untrusted or unknown sources, especially those mimicking internal package names. Verify package names and sources carefully to prevent dependency confusion attacks. Since no official patch or fix is available, remediation involves correcting package resolver configurations to prioritize private/internal registries and removing any instances of this malicious package. Monitor package dependencies for suspicious or unexpected additions. Patch status is not yet confirmed — check the vendor advisory or trusted security sources for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10764
Osv Schema Version
1.7.4
Aliases
["GHSA-j5f4-f3f3-634h"]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a5b60912d1edb114c84a447

Added to database: 07/18/2026, 11:16:33 UTC

Last enriched: 08/07/2026, 00:29:56 UTC

Last updated: 09/01/2026, 21:14:53 UTC

Views: 59

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses