Malicious code in syft-acp-core (npm)
The syft-acp-core npm package is a malicious package published to the public npm registry as part of a dependency confusion reconnaissance campaign. It mimics an internal package name to trick misconfigured resolvers into installing it instead of the intended private package. The package includes a preinstall hook that runs automatically during npm install, which collects the installer's public IP and other default PII (hostname, OS username, runtime metadata) and sends this telemetry to an attacker-controlled Sentry project. This behavior is consistent with reconnaissance rather than direct exploitation. The malicious payload is identical to a previous campaign and uses hardcoded attacker-controlled Sentry endpoints.
AI Analysis
Technical Summary
The syft-acp-core package was published to npm by an attacker impersonating an internal package name to exploit dependency confusion. It declares a preinstall hook that executes automatically during installation, running a script that initializes the @sentry/node client with a hardcoded attacker-controlled DSN and sendDefaultPii enabled. The script collects the installer's public IP by querying Cloudflare's trace endpoint and triggers a synthetic exception to send telemetry including IP, hostname, OS username, and runtime metadata to the attacker's Sentry project. Each package namespace in the campaign uses distinct Sentry project IDs to attribute installs to specific organizations. This package's payload is byte-for-byte identical to a previous campaign named 'click2ai', sharing the same Sentry organization and maintainer identity. The attack is reconnaissance-focused, collecting environment data rather than delivering a direct exploit or malware payload.
Potential Impact
The malicious package leaks sensitive telemetry and personally identifiable information (PII) from the host environment during installation, including public IP address, hostname, OS username, and runtime environment metadata. This data is sent to an attacker-controlled Sentry project, enabling the attacker to identify and attribute installations to specific victim organizations. This can facilitate further targeted attacks or reconnaissance. There is no indication of direct code execution beyond the preinstall hook or further exploitation payloads in this package.
Mitigation Recommendations
Users should avoid installing the syft-acp-core package from the public npm registry, especially if they rely on private internal packages with similar names. Organizations should audit their dependency resolution configurations to prevent dependency confusion attacks by ensuring private packages are resolved correctly and not overridden by public packages. Since no official patch or fix is indicated, mitigation focuses on configuration hygiene and package source verification. Monitor for unexpected preinstall hooks in dependencies and consider using tools that detect malicious or suspicious packages. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.
Malicious code in syft-acp-core (npm)
Description
The syft-acp-core npm package is a malicious package published to the public npm registry as part of a dependency confusion reconnaissance campaign. It mimics an internal package name to trick misconfigured resolvers into installing it instead of the intended private package. The package includes a preinstall hook that runs automatically during npm install, which collects the installer's public IP and other default PII (hostname, OS username, runtime metadata) and sends this telemetry to an attacker-controlled Sentry project. This behavior is consistent with reconnaissance rather than direct exploitation. The malicious payload is identical to a previous campaign and uses hardcoded attacker-controlled Sentry endpoints.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The syft-acp-core package was published to npm by an attacker impersonating an internal package name to exploit dependency confusion. It declares a preinstall hook that executes automatically during installation, running a script that initializes the @sentry/node client with a hardcoded attacker-controlled DSN and sendDefaultPii enabled. The script collects the installer's public IP by querying Cloudflare's trace endpoint and triggers a synthetic exception to send telemetry including IP, hostname, OS username, and runtime metadata to the attacker's Sentry project. Each package namespace in the campaign uses distinct Sentry project IDs to attribute installs to specific organizations. This package's payload is byte-for-byte identical to a previous campaign named 'click2ai', sharing the same Sentry organization and maintainer identity. The attack is reconnaissance-focused, collecting environment data rather than delivering a direct exploit or malware payload.
Potential Impact
The malicious package leaks sensitive telemetry and personally identifiable information (PII) from the host environment during installation, including public IP address, hostname, OS username, and runtime environment metadata. This data is sent to an attacker-controlled Sentry project, enabling the attacker to identify and attribute installations to specific victim organizations. This can facilitate further targeted attacks or reconnaissance. There is no indication of direct code execution beyond the preinstall hook or further exploitation payloads in this package.
Mitigation Recommendations
Users should avoid installing the syft-acp-core package from the public npm registry, especially if they rely on private internal packages with similar names. Organizations should audit their dependency resolution configurations to prevent dependency confusion attacks by ensuring private packages are resolved correctly and not overridden by public packages. Since no official patch or fix is indicated, mitigation focuses on configuration hygiene and package source verification. Monitor for unexpected preinstall hooks in dependencies and consider using tools that detect malicious or suspicious packages. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10765
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-289v-6j56-44w8"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a5b60912d1edb114c84a443
Added to database: 07/18/2026, 11:16:33 UTC
Last enriched: 08/07/2026, 00:29:47 UTC
Last updated: 08/31/2026, 04:23:04 UTC
Views: 50
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.