@convera/ui-shared@0.0.3
Malicious code in @convera/ui-shared (npm)
T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages
Analysis
On installation the package's preinstall.js makes an HTTPS GET request to an out-of-band collaborator domain (am0f14nl6o1nqwrngbrq33amfdl496xv[.]oastify[.]com), sending the installing machine's hostname and username. The host-fingerprint beacon runs automatically during npm install.
- analyzed by
- Leitwacht
- first seen
- May 27, 2026, 03:33 AM
- analyzed
- May 27, 2026, 04:36 AM
Related advisories
- @convera/ui-shared@0.0.2 same package
- msc-terminal@3.2.0
- @asavie/i18n@99.0.3
- forge-jsxy@1.0.91
- swiper_angular@5.9999.0
- fundraiserserv@28.0.0
- preferenceslifecycle-paypal@28.0.0
- client-cookies-agent@99.9.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.