LWA-2026-12307 MAL-2026-16360 ↗ confirmed malware

@uh-platform/nadaver@102.0.0

Malicious code in @uh-platform/nadaver (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package's preinstall hook runs index.js, which executes a curl request to hxxp://$(hostname).nadaver[.]pa33pg1od9cr4ffnrzec8864jvpmdd12[.]oastify[.]com/ — a Burp Collaborator (oastify) callback domain. On every install the victim's hostname is transmitted to this attacker-controlled endpoint. The package is a 484-byte stub with no real functionality; its sole purpose is the install-time beacon.

analyzed by
Leitwacht
first seen
Sep 21, 2026, 06:26 PM
analyzed
Sep 21, 2026, 06:27 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.