syft-acp-atoms@1.0.0
Malicious code in syft-acp-atoms (npm)
T1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The postinstall hook runs beacon.js, which collects the installer's hostname, username, and working directory, hex-encodes them, and sends them via an HTTPS GET to exzotiqq[.]com (path /?syft-acp-atoms_<hex>). The package phones home with host metadata on every install. No credentials or files are exfiltrated.
- analyzed by
- Leitwacht
- first seen
- Aug 6, 2026, 01:18 PM
- analyzed
- Aug 6, 2026, 01:19 PM
Related advisories
- streak-cache-map@1.0.0
- app-api-sdk@2.1.7
- hardhat-set@2.21.0
- ded-pwa-bnpl-forms-demo@35.9.6
- devplatform-spa-plugin-s3-feature-toggle@35.7.1
- devplatform-cli-spa@35.7.8
- devplatform-http-client@35.8.6
- dolyame-boxy-independent-bnpl-mobile-application@35.9.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.