Malicious code in tme-xca (npm)
The tme-xca npm package version 3.0.0 is a malicious package published as part of a dependency confusion campaign. It includes a preinstall hook that executes code to collect and send the installer's public IP address and host telemetry, including personally identifiable information, to an attacker-controlled Sentry endpoint. This behavior occurs automatically during npm install, before application code runs. The package impersonates internal package namespaces to trick misconfigured resolvers into installing it instead of legitimate private dependencies. The malicious payload is identical across packages from the same attacker account, differing only in package name and target Sentry project. Installation of this package compromises the host, potentially exposing secrets and keys stored on the system.
AI Analysis
Technical Summary
The tme-xca package (npm, version 3.0.0) was published by an attacker under the user 'click2ai' as part of a dependency confusion and reconnaissance campaign targeting organizations using internal 'tme' namespaces. The package declares a preinstall hook that runs automatically on npm install, executing a script that initializes the @sentry/node client with a hardcoded attacker-controlled DSN. This script collects the installer's public egress IP by querying Cloudflare's trace endpoint and attaches it along with default PII (hostname, OS username, runtime metadata) to a deliberately triggered error event. This event is sent to the attacker's Sentry project, enabling attribution of successful installs to specific victims. The package's source code also hardcodes the same DSN with sendDefaultPii enabled, causing any usage of its error reporting API without custom DSN configuration to leak exceptions and PII to the attacker. The malicious behavior is consistent across all packages published by this account, differing only in package name and Sentry project ID. The compromise is severe enough that any system with this package installed should be considered fully compromised.
Potential Impact
Installation of tme-xca version 3.0.0 results in automatic execution of malicious code that collects and exfiltrates the installer's public IP address and host environment PII to an attacker-controlled Sentry endpoint. This compromises confidentiality by leaking sensitive host information without user consent. The presence of this package indicates a successful dependency confusion attack, potentially exposing internal organizational details. The attacker can attribute installs to specific organizations via distinct Sentry project IDs. According to external malware analysis, any computer with this package installed should be considered fully compromised, with all secrets and keys on that system requiring immediate rotation. The malicious code runs before application code, increasing risk of undetected compromise.
Mitigation Recommendations
No official patch or fix is available for this malicious package. The recommended mitigation is to immediately remove the tme-xca package version 3.0.0 from all affected systems. Because the package executes code at install time and may have granted the attacker extensive access, it is critical to assume full system compromise. All secrets, credentials, and keys stored on the affected systems should be rotated from a secure, uncompromised environment. Organizations should audit their dependency resolution configurations to prevent dependency confusion attacks by ensuring private namespaces are not resolvable to public packages. Monitoring and blocking suspicious packages published under impersonated namespaces is advised. Patch status is not applicable as this is a malicious package, not a vulnerability with a vendor fix.
Malicious code in tme-xca (npm)
Description
The tme-xca npm package version 3.0.0 is a malicious package published as part of a dependency confusion campaign. It includes a preinstall hook that executes code to collect and send the installer's public IP address and host telemetry, including personally identifiable information, to an attacker-controlled Sentry endpoint. This behavior occurs automatically during npm install, before application code runs. The package impersonates internal package namespaces to trick misconfigured resolvers into installing it instead of legitimate private dependencies. The malicious payload is identical across packages from the same attacker account, differing only in package name and target Sentry project. Installation of this package compromises the host, potentially exposing secrets and keys stored on the system.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The tme-xca package (npm, version 3.0.0) was published by an attacker under the user 'click2ai' as part of a dependency confusion and reconnaissance campaign targeting organizations using internal 'tme' namespaces. The package declares a preinstall hook that runs automatically on npm install, executing a script that initializes the @sentry/node client with a hardcoded attacker-controlled DSN. This script collects the installer's public egress IP by querying Cloudflare's trace endpoint and attaches it along with default PII (hostname, OS username, runtime metadata) to a deliberately triggered error event. This event is sent to the attacker's Sentry project, enabling attribution of successful installs to specific victims. The package's source code also hardcodes the same DSN with sendDefaultPii enabled, causing any usage of its error reporting API without custom DSN configuration to leak exceptions and PII to the attacker. The malicious behavior is consistent across all packages published by this account, differing only in package name and Sentry project ID. The compromise is severe enough that any system with this package installed should be considered fully compromised.
Potential Impact
Installation of tme-xca version 3.0.0 results in automatic execution of malicious code that collects and exfiltrates the installer's public IP address and host environment PII to an attacker-controlled Sentry endpoint. This compromises confidentiality by leaking sensitive host information without user consent. The presence of this package indicates a successful dependency confusion attack, potentially exposing internal organizational details. The attacker can attribute installs to specific organizations via distinct Sentry project IDs. According to external malware analysis, any computer with this package installed should be considered fully compromised, with all secrets and keys on that system requiring immediate rotation. The malicious code runs before application code, increasing risk of undetected compromise.
Mitigation Recommendations
No official patch or fix is available for this malicious package. The recommended mitigation is to immediately remove the tme-xca package version 3.0.0 from all affected systems. Because the package executes code at install time and may have granted the attacker extensive access, it is critical to assume full system compromise. All secrets, credentials, and keys stored on the affected systems should be rotated from a secure, uncompromised environment. Organizations should audit their dependency resolution configurations to prevent dependency confusion attacks by ensuring private namespaces are not resolvable to public packages. Monitoring and blocking suspicious packages published under impersonated namespaces is advised. Patch status is not applicable as this is a malicious package, not a vulnerability with a vendor fix.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10236
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-w846-5p2c-7hwq"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a55ff7168715ace432f2300
Added to database: 07/14/2026, 09:20:49 UTC
Last enriched: 07/14/2026, 09:37:07 UTC
Last updated: 07/24/2026, 14:30:36 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.