LWA-2026-12383 MAL-2026-17156 ↗ confirmed malware

aliftech-ui@99.9.9

Malicious code in aliftech-ui (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols

Analysis

The package's postinstall hook (postinstall.js) runs on install and exfiltrates host metadata: it reads the machine hostname and the current OS username and sends them to the attacker-controlled endpoint hxxps://webhook[.]site/539f8bb9-497a-4104-92f7-f95a77204cc2/<hostname>/<username> via an HTTPS GET. The package is a minimal 526-byte file with no legitimate functionality beyond this beacon.

analyzed by
Leitwacht
first seen
Sep 24, 2026, 11:06 AM
analyzed
Sep 24, 2026, 11:07 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.