LWA-2026-0202 MAL-2026-3724 ↗ confirmed malware

@convera/ui-shared@0.0.3

Malicious code in @convera/ui-shared (npm)

T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages

Analysis

On installation the package's preinstall.js makes an HTTPS GET request to an out-of-band collaborator domain (am0f14nl6o1nqwrngbrq33amfdl496xv[.]oastify[.]com), sending the installing machine's hostname and username. The host-fingerprint beacon runs automatically during npm install.

analyzed by
Leitwacht
first seen
May 27, 2026, 03:33 AM
analyzed
May 27, 2026, 04:36 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.