LWA-2026-10615 MAL-2026-10764 ↗ confirmed malware

syft-acp-atoms@1.0.0

Malicious code in syft-acp-atoms (npm)

T1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The postinstall hook runs beacon.js, which collects the installer's hostname, username, and working directory, hex-encodes them, and sends them via an HTTPS GET to exzotiqq[.]com (path /?syft-acp-atoms_<hex>). The package phones home with host metadata on every install. No credentials or files are exfiltrated.

analyzed by
Leitwacht
first seen
Aug 6, 2026, 01:18 PM
analyzed
Aug 6, 2026, 01:19 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.