@sentry-internals / @sentry-browser-sdk profiling-node typosquat via forged Sentry events
On 2026-06-03 Nutrient (PSPDFKit) caught a novel two-stage attack: an attacker submitted forged Sentry events through a public browser DSN, displaying "remediation" runbook text that instructed responders (and AI agents) to run npx @sentry-internals/profiling-node --diagnose. The typosquat - and its sibling @sentry-browser-sdk/profiling-node (v1.0.0–1.0.5) - exfiltrated env, working-directory, and dev-context data to advisory-tracker.com before npm replaced both with 0.0.1-security holders.
Versions named here: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5