LWA-2026-12363 MAL-2026-16477 ↗ confirmed malware

com.apple.unityplugin.storekit@1.0.1

Malicious code in com.apple.unityplugin.storekit (npm)

T1071.001 · Web ProtocolsT1082 · System Information Discovery

Analysis

The package impersonates Apple's StoreKit Unity plugin but ships only a 372-byte index.js that, when required, sends an HTTPS GET to dapnhid534ch06s9vpm0mbg1httu5gytc[.]oast[.]fun with the package name, OS platform, and hostname as query parameters — a host-metadata beacon to an attacker-controlled OAST domain.

analyzed by
Leitwacht
first seen
Sep 23, 2026, 08:36 AM
analyzed
Sep 23, 2026, 08:37 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.