MAL-2026-10398

    Dashboard / Malicious Package / MAL-2026-10398

    MAL-2026-10398

    Published: 13 Jul 2026Last Modified: 13 Jul 2026

    Summary: Malicious code in @db-tools/main-app (npm)

    Details: Source: amazon-inspector (2d3b0edc39a389f4099895c647f0cdccbb08c85e56835670468e7a989b172e9f) package.json declares a preinstall hook `npm install @sentry/node && node examples/verify.js` that fires on every `npm install`. examples/verify.js calls the library's init() with no DSN, which falls back to a hardcoded DEFAULT_DSN in src/index.js (`https://[email protected]/4511652667785296`). verify.js then invokes setUserFromPublicIp() which fetches the installer's public egress IP from `https://www.cloudflare.com/cdn-cgi/trace`, attaches it as Sentry user context, throws a synthetic exception, and flushes it to the author-controlled Sentry project. The installer has no opportunity to configure or opt out — the data flow is unconditional and non-consensual on `npm install`. Separately, the exported init() API uses the same hardcoded DEFAULT_DSN as its final fallback (after options.dsn and process.env.SENTRY_DSN) and sets `sendDefaultPii: true`, so any consumer that uses the library without explicitly supplying a DSN silently routes their application's exceptions and PII to the same author-owned Sentry project, with no disclosure in the README.

    Affected packages

    Package

    Name: @db-tools/main-app

    Purl: pkg:npm/%40db-tools/main-app

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    2026.6.30
    MAL-2026-10398 | CVE-DB