LWA-2026-12303 MAL-2026-16362 ↗ confirmed malware

@uh-platform/webcard@99.0.0

Malicious code in @uh-platform/webcard (npm)

T1059.007 · JavaScriptT1071.001 · Web Protocols

Analysis

The package's preinstall hook runs index.js, which executes a curl command that makes an outbound HTTP request to the interaction/beacon host pa33pg1od9cr4ffnrzec8864jvpmdd12[.]oastify[.]com at install time. Installing the package triggers this callback to the remote endpoint, beaconing the installation to an attacker-controlled host.

analyzed by
Leitwacht
first seen
Sep 21, 2026, 05:17 PM
analyzed
Sep 21, 2026, 05:18 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.