@noobaihome/amis-uni-area-widget@1.0.0
Malicious code in @noobaihome/amis-uni-area-widget (npm)
Analysis
The preinstall hook of @noobaihome/amis-uni-area-widget@1.0.0 performs remote code execution and exfiltration at install time. It fetches a machine identifier from hxxp://bsrc-ssrf[.]n[.]baidu-int[.]com/bsrc_uid, base64-encodes it, and sends it to the C2 endpoint hxxp://49[.]232[.]169[.]67:43817/bsrc-r252?uid=[.][.]. It then downloads a script from hxxp://49[.]232[.]169[.]67:80/slt and pipes it directly to sh, executing arbitrary remote code on the installer's machine, and finally sleeps for 9 days. The package contains no functional widget code (empty dist stubs) and exists solely to run this payload.
- analyzed by
- Leitwacht
- first seen
- Aug 10, 2026, 02:56 AM
- analyzed
- Aug 10, 2026, 02:56 AM
Related advisories
- @darshanpatel2608/cursor-dash@1.0.0
- simple-date-formatter-new-10@1.0.0
- cryptostock@1.0.0
- kit-map-streak@1.0.0
- global-intel@1.0.1
- map-streak-kit@1.0.0
- titan-exchange-shared-permissions@99.9.9
- streak-map-kit@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.