Malicious code in syft-acp-uikit (npm)
The syft-acp-uikit npm package is a malicious package published as part of a dependency confusion campaign. It impersonates an internal package name to trick misconfigured resolvers into installing it instead of the legitimate private package. The package includes a preinstall script that executes automatically during npm install, which collects the host's public IP and other PII and sends this telemetry to an attacker-controlled Sentry endpoint. This behavior is consistent with reconnaissance activity to identify successful installs in targeted organizations.
AI Analysis
Technical Summary
The syft-acp-uikit package was published to the npm registry by an attacker impersonating an internal package naming convention to exploit dependency confusion. It contains a preinstall hook that runs a script initializing the @sentry/node client with a hardcoded attacker-controlled Sentry DSN and sendDefaultPii enabled. The script fetches the installing host's public egress IP from Cloudflare, triggers a runtime error, and sends a Sentry event containing the IP and default PII such as hostname, OS username, and environment metadata to the attacker's Sentry project. This telemetry beacon allows the attacker to identify which organizations installed the package. The package is part of a broader campaign using similar tactics and infrastructure.
Potential Impact
The malicious package exfiltrates sensitive telemetry data including the public IP address, hostname, OS username, and runtime environment metadata from any system that installs it. This data is sent to an attacker-controlled Sentry project, enabling the attacker to perform reconnaissance on victim environments. While no direct code execution beyond the preinstall script is described, the automatic execution of this script during npm install can lead to unintended data leakage and potential further targeting based on the collected information.
Mitigation Recommendations
No official patch or fix is available since this is a malicious package published to a public registry. The primary mitigation is to audit and restrict package sources to trusted registries and verify package provenance before installation. Organizations should ensure their dependency resolution is correctly configured to avoid dependency confusion attacks by prioritizing private/internal registries over public ones for internal package names. Additionally, monitoring for unexpected preinstall scripts in dependencies can help detect similar threats.
Malicious code in syft-acp-uikit (npm)
Description
The syft-acp-uikit npm package is a malicious package published as part of a dependency confusion campaign. It impersonates an internal package name to trick misconfigured resolvers into installing it instead of the legitimate private package. The package includes a preinstall script that executes automatically during npm install, which collects the host's public IP and other PII and sends this telemetry to an attacker-controlled Sentry endpoint. This behavior is consistent with reconnaissance activity to identify successful installs in targeted organizations.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The syft-acp-uikit package was published to the npm registry by an attacker impersonating an internal package naming convention to exploit dependency confusion. It contains a preinstall hook that runs a script initializing the @sentry/node client with a hardcoded attacker-controlled Sentry DSN and sendDefaultPii enabled. The script fetches the installing host's public egress IP from Cloudflare, triggers a runtime error, and sends a Sentry event containing the IP and default PII such as hostname, OS username, and environment metadata to the attacker's Sentry project. This telemetry beacon allows the attacker to identify which organizations installed the package. The package is part of a broader campaign using similar tactics and infrastructure.
Potential Impact
The malicious package exfiltrates sensitive telemetry data including the public IP address, hostname, OS username, and runtime environment metadata from any system that installs it. This data is sent to an attacker-controlled Sentry project, enabling the attacker to perform reconnaissance on victim environments. While no direct code execution beyond the preinstall script is described, the automatic execution of this script during npm install can lead to unintended data leakage and potential further targeting based on the collected information.
Mitigation Recommendations
No official patch or fix is available since this is a malicious package published to a public registry. The primary mitigation is to audit and restrict package sources to trusted registries and verify package provenance before installation. Organizations should ensure their dependency resolution is correctly configured to avoid dependency confusion attacks by prioritizing private/internal registries over public ones for internal package names. Additionally, monitoring for unexpected preinstall scripts in dependencies can help detect similar threats.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10766
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-rvgp-458h-wjc3"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a5b608f2d1edb114c84a30f
Added to database: 07/18/2026, 11:16:31 UTC
Last enriched: 08/07/2026, 00:29:36 UTC
Last updated: 08/29/2026, 03:45:21 UTC
Views: 74
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.