@convera/ui-shared@0.0.3
Malicious code in @convera/ui-shared (npm)
T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages
Analysis
On installation the package's preinstall.js makes an HTTPS GET request to an out-of-band collaborator domain (am0f14nl6o1nqwrngbrq33amfdl496xv[.]oastify[.]com), sending the installing machine's hostname and username. The host-fingerprint beacon runs automatically during npm install.
- analyzed by
- Leitwacht
- first seen
- May 27, 2026, 03:33 AM
- analyzed
- May 27, 2026, 04:36 AM
Related advisories
- @convera/ui-shared@0.0.2 same package
- msc-terminal@3.2.0
- @asavie/i18n@99.0.3
- forge-jsxy@1.0.91
- eslint-plugin-vitest-ts@1.0.4
- fundraiserserv@28.0.0
- relativity-pdfjs-dist@99.9.9
- client-cookies-agent@99.9.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.