syft-acp-core@1.0.0
Malicious code in syft-acp-core (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The package's postinstall hook runs beacon.js, which collects the installer's hostname, OS username, and current working directory, hex-encodes them, and transmits them via an HTTPS GET to exzotiqq[.]com (port 443) in the request path. The package has no other functionality; its sole purpose is this install-time host-fingerprint beacon to the remote host.
- analyzed by
- Leitwacht
- first seen
- Aug 6, 2026, 01:40 PM
- analyzed
- Aug 6, 2026, 01:40 PM
Related advisories
- syft-acp-atoms@1.0.0
- streak-cache-map@1.0.0
- app-api-sdk@2.1.7
- hardhat-set@2.21.0
- ded-pwa-bnpl-forms-demo@35.9.6
- devplatform-spa-plugin-s3-feature-toggle@35.7.1
- devplatform-cli-spa@35.7.8
- devplatform-http-client@35.8.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.