Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in tme-error (npm)

0
Critical
Published: 07/06/2026 (07/06/2026, 00:00:00 UTC)
Source: GCVE Database
Product: tme-error

Description

The tme-error npm package, published by a malicious actor, impersonates an internal package namespace to exploit dependency confusion. It includes a preinstall hook that executes code during npm install, sending the installer's public IP, hostname, username, and runtime metadata to an attacker-controlled Sentry endpoint without user consent. This behavior enables reconnaissance on victims and potential data exfiltration. The package also silently redirects error reporting to the attacker's Sentry project if consumers call its init() function without specifying their own DSN. The affected version is 2.8.42. Removal alone may not fully remediate the compromise, and secrets should be rotated.

Affected software

npmghsa
tme-error
Affected versions
=2.8.42

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/14/2026, 09:37:17 UTC

Technical Analysis

The tme-error package was published to npm by a user 'click2ai' as part of a dependency confusion reconnaissance campaign targeting organizations using a 'tme' internal namespace. The package's preinstall hook runs automatically during npm install, executing a script that initializes the @sentry/node client with a hardcoded attacker-controlled DSN and sends telemetry including the installer's public IP (resolved via Cloudflare), hostname, OS username, and Node.js runtime metadata to the attacker's Sentry project. This data exfiltration occurs without user consent and before application code runs. The package also exports an init() function that, if called without a DSN, routes error reports to the attacker's Sentry project, misleading consumers. The install-time payload is identical across all packages published by this actor, differing only in package name and target DSN. The affected version is exactly 2.8.42. Security advisories warn that any system with this package installed should be considered fully compromised, with immediate secret rotation recommended.

Potential Impact

Installation of this malicious package results in unauthorized exfiltration of sensitive host telemetry including public IP address, hostname, OS username, and runtime environment metadata to an attacker-controlled Sentry endpoint. This compromises confidentiality and may enable targeted follow-up attacks. The package also hijacks error reporting by redirecting captured exceptions to the attacker's Sentry project if consumers use the init() function without specifying their own DSN, potentially leaking application error data. Systems with this package installed are considered fully compromised, and secrets stored on those systems should be rotated immediately. Removal of the package alone does not guarantee full remediation.

Mitigation Recommendations

No official patch or fix is available for this malicious package. The recommended mitigation is to immediately remove the tme-error package version 2.8.42 from all affected systems. Because the package executes code at install time that exfiltrates sensitive data and may compromise the system, all secrets and keys stored on affected computers should be rotated from a different, trusted machine. Monitor for any signs of further compromise. Avoid installing packages from untrusted or suspicious sources, especially those mimicking internal namespaces. Verify package provenance before installation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10235
Osv Schema Version
1.7.4
Aliases
["GHSA-89rr-3jxw-7hhm"]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a55ff7168715ace432f2305

Added to database: 07/14/2026, 09:20:49 UTC

Last enriched: 07/14/2026, 09:37:17 UTC

Last updated: 07/24/2026, 19:51:31 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses