LWA-2026-10616 MAL-2026-10765 ↗ confirmed malware

syft-acp-core@1.0.0

Malicious code in syft-acp-core (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package's postinstall hook runs beacon.js, which collects the installer's hostname, OS username, and current working directory, hex-encodes them, and transmits them via an HTTPS GET to exzotiqq[.]com (port 443) in the request path. The package has no other functionality; its sole purpose is this install-time host-fingerprint beacon to the remote host.

analyzed by
Leitwacht
first seen
Aug 6, 2026, 01:40 PM
analyzed
Aug 6, 2026, 01:40 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.