aliftech-ui@99.9.9
Malicious code in aliftech-ui (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols
Analysis
The package's postinstall hook (postinstall.js) runs on install and exfiltrates host metadata: it reads the machine hostname and the current OS username and sends them to the attacker-controlled endpoint hxxps://webhook[.]site/539f8bb9-497a-4104-92f7-f95a77204cc2/<hostname>/<username> via an HTTPS GET. The package is a minimal 526-byte file with no legitimate functionality beyond this beacon.
- analyzed by
- Leitwacht
- first seen
- Sep 24, 2026, 11:06 AM
- analyzed
- Sep 24, 2026, 11:07 AM
Related advisories
- @nf-addons/am-global-header@9.9.10
- simple-date-formatter-new-15@1.0.0
- n8n-nodes-flowstats@1.0.0
- @insiderintelligence/componentlibrary@9.9.10
- simple-date-formatter-new-14@1.0.0
- simple-date-formatter-new-13@1.0.0
- simple-date-formatter-new-11@1.0.0
- eslint-config-compact-base@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.