@convera/ui-shared@0.0.2
Malicious code in @convera/ui-shared (npm)
T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages
Analysis
On installation the package's preinstall.js performs DNS-based exfiltration, collecting the installing machine's hostname and username and tunnelling them via DNS lookups to an out-of-band listener subdomain under oastify[.]com (am0f14nl6o1nqwrngbrq33amfdl496xv[.]oastify[.]com). It runs automatically during npm install.
- analyzed by
- Leitwacht
- first seen
- May 27, 2026, 03:33 AM
- analyzed
- May 27, 2026, 04:37 AM
Related advisories
- @convera/ui-shared@0.0.3 same package
- msc-terminal@3.2.0
- @asavie/i18n@99.0.3
- forge-jsxy@1.0.91
- eslint-plugin-vitest-ts@1.0.4
- fundraiserserv@28.0.0
- relativity-pdfjs-dist@99.9.9
- client-cookies-agent@99.9.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.