sentrykit@30.0.0
Malicious code in sentrykit (npm)
Analysis
This package is a dependency-confusion / combosquat attack. The tarball itself is a small shell containing a benign placeholder, but package.json declares a self-dependency pointing to hxxps://repo[.]securityctrl[.]com/sentrykit — an external, non-npm HTTPS URL under attacker control. When npm installs this package and resolves its dependency tree, it fetches and installs the payload from that remote server automatically. The dependency fetched from that URL has been independently confirmed as malware. The package name "sentrykit" mimics the legitimate Sentry SDK namespace to trick developers into installing it.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 05:32 PM
- analyzed
- Jun 13, 2026, 05:33 PM
Related advisories
- search-reservation@55.0.0
- rollup-runtime-polyfill-core@0.13.5
- rollup-packages-polyfill-core@0.5.0
- rollup-plugin-polyfill-connect@1.0.1
- ring-device-settings-library@45.0.0
- request-js-validator@1.0.2
- macos-ci-utils@1.0.1
- redirect-azlazy@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.