Malicious code in tme-error (npm)
The tme-error npm package, published by a malicious actor, impersonates an internal package namespace to exploit dependency confusion. It includes a preinstall hook that executes code during npm install, sending the installer's public IP, hostname, username, and runtime metadata to an attacker-controlled Sentry endpoint without user consent. This behavior enables reconnaissance on victims and potential data exfiltration. The package also silently redirects error reporting to the attacker's Sentry project if consumers call its init() function without specifying their own DSN. The affected version is 2.8.42. Removal alone may not fully remediate the compromise, and secrets should be rotated.
AI Analysis
Technical Summary
The tme-error package was published to npm by a user 'click2ai' as part of a dependency confusion reconnaissance campaign targeting organizations using a 'tme' internal namespace. The package's preinstall hook runs automatically during npm install, executing a script that initializes the @sentry/node client with a hardcoded attacker-controlled DSN and sends telemetry including the installer's public IP (resolved via Cloudflare), hostname, OS username, and Node.js runtime metadata to the attacker's Sentry project. This data exfiltration occurs without user consent and before application code runs. The package also exports an init() function that, if called without a DSN, routes error reports to the attacker's Sentry project, misleading consumers. The install-time payload is identical across all packages published by this actor, differing only in package name and target DSN. The affected version is exactly 2.8.42. Security advisories warn that any system with this package installed should be considered fully compromised, with immediate secret rotation recommended.
Potential Impact
Installation of this malicious package results in unauthorized exfiltration of sensitive host telemetry including public IP address, hostname, OS username, and runtime environment metadata to an attacker-controlled Sentry endpoint. This compromises confidentiality and may enable targeted follow-up attacks. The package also hijacks error reporting by redirecting captured exceptions to the attacker's Sentry project if consumers use the init() function without specifying their own DSN, potentially leaking application error data. Systems with this package installed are considered fully compromised, and secrets stored on those systems should be rotated immediately. Removal of the package alone does not guarantee full remediation.
Mitigation Recommendations
No official patch or fix is available for this malicious package. The recommended mitigation is to immediately remove the tme-error package version 2.8.42 from all affected systems. Because the package executes code at install time that exfiltrates sensitive data and may compromise the system, all secrets and keys stored on affected computers should be rotated from a different, trusted machine. Monitor for any signs of further compromise. Avoid installing packages from untrusted or suspicious sources, especially those mimicking internal namespaces. Verify package provenance before installation.
Malicious code in tme-error (npm)
Description
The tme-error npm package, published by a malicious actor, impersonates an internal package namespace to exploit dependency confusion. It includes a preinstall hook that executes code during npm install, sending the installer's public IP, hostname, username, and runtime metadata to an attacker-controlled Sentry endpoint without user consent. This behavior enables reconnaissance on victims and potential data exfiltration. The package also silently redirects error reporting to the attacker's Sentry project if consumers call its init() function without specifying their own DSN. The affected version is 2.8.42. Removal alone may not fully remediate the compromise, and secrets should be rotated.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The tme-error package was published to npm by a user 'click2ai' as part of a dependency confusion reconnaissance campaign targeting organizations using a 'tme' internal namespace. The package's preinstall hook runs automatically during npm install, executing a script that initializes the @sentry/node client with a hardcoded attacker-controlled DSN and sends telemetry including the installer's public IP (resolved via Cloudflare), hostname, OS username, and Node.js runtime metadata to the attacker's Sentry project. This data exfiltration occurs without user consent and before application code runs. The package also exports an init() function that, if called without a DSN, routes error reports to the attacker's Sentry project, misleading consumers. The install-time payload is identical across all packages published by this actor, differing only in package name and target DSN. The affected version is exactly 2.8.42. Security advisories warn that any system with this package installed should be considered fully compromised, with immediate secret rotation recommended.
Potential Impact
Installation of this malicious package results in unauthorized exfiltration of sensitive host telemetry including public IP address, hostname, OS username, and runtime environment metadata to an attacker-controlled Sentry endpoint. This compromises confidentiality and may enable targeted follow-up attacks. The package also hijacks error reporting by redirecting captured exceptions to the attacker's Sentry project if consumers use the init() function without specifying their own DSN, potentially leaking application error data. Systems with this package installed are considered fully compromised, and secrets stored on those systems should be rotated immediately. Removal of the package alone does not guarantee full remediation.
Mitigation Recommendations
No official patch or fix is available for this malicious package. The recommended mitigation is to immediately remove the tme-error package version 2.8.42 from all affected systems. Because the package executes code at install time that exfiltrates sensitive data and may compromise the system, all secrets and keys stored on affected computers should be rotated from a different, trusted machine. Monitor for any signs of further compromise. Avoid installing packages from untrusted or suspicious sources, especially those mimicking internal namespaces. Verify package provenance before installation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10235
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-89rr-3jxw-7hhm"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a55ff7168715ace432f2305
Added to database: 07/14/2026, 09:20:49 UTC
Last enriched: 07/14/2026, 09:37:17 UTC
Last updated: 07/24/2026, 19:51:31 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.