@convera/ui-shared@0.0.2
Malicious code in @convera/ui-shared (npm)
T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages
Analysis
On installation the package's preinstall.js performs DNS-based exfiltration, collecting the installing machine's hostname and username and tunnelling them via DNS lookups to an out-of-band listener subdomain under oastify[.]com (am0f14nl6o1nqwrngbrq33amfdl496xv[.]oastify[.]com). It runs automatically during npm install.
- analyzed by
- Leitwacht
- first seen
- May 27, 2026, 03:33 AM
- analyzed
- May 27, 2026, 04:37 AM
Related advisories
- @convera/ui-shared@0.0.3 same package
- msc-terminal@3.2.0
- @asavie/i18n@99.0.3
- forge-jsxy@1.0.91
- swiper_angular@5.9999.0
- fundraiserserv@28.0.0
- preferenceslifecycle-paypal@28.0.0
- client-cookies-agent@99.9.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.