LWA-2026-5099 confirmed malware

sentrykit@30.0.0

Malicious code in sentrykit (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

This package is a dependency-confusion / combosquat attack. The tarball itself is a small shell containing a benign placeholder, but package.json declares a self-dependency pointing to hxxps://repo[.]securityctrl[.]com/sentrykit — an external, non-npm HTTPS URL under attacker control. When npm installs this package and resolves its dependency tree, it fetches and installs the payload from that remote server automatically. The dependency fetched from that URL has been independently confirmed as malware. The package name "sentrykit" mimics the legitimate Sentry SDK namespace to trick developers into installing it.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 05:32 PM
analyzed
Jun 13, 2026, 05:33 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.