com.apple.unityplugin.storekit@1.0.1
Malicious code in com.apple.unityplugin.storekit (npm)
T1071.001 · Web ProtocolsT1082 · System Information Discovery
Analysis
The package impersonates Apple's StoreKit Unity plugin but ships only a 372-byte index.js that, when required, sends an HTTPS GET to dapnhid534ch06s9vpm0mbg1httu5gytc[.]oast[.]fun with the package name, OS platform, and hostname as query parameters — a host-metadata beacon to an attacker-controlled OAST domain.
- analyzed by
- Leitwacht
- first seen
- Sep 23, 2026, 08:36 AM
- analyzed
- Sep 23, 2026, 08:37 AM
Related advisories
- @memtensor/memos-cloud-openclaw-plugin@0.1.23
- my-company-device@0.1.0
- efhthrthrthregerht@99.9.9
- faceplate-docs@99.9.9
- eslint-plugin-i18n-shreddit@99.9.9
- @tvg-mar/utils@9.9.10
- @tvg-mar/tvg-promos-atomic-ui@9.9.10
- @tvg-mar/promos-gtm@9.9.10
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.