@birbalo/aliftech-ui@99.9.9
Malicious code in @birbalo/aliftech-ui (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1567 · Exfiltration Over Web Service
Analysis
The postinstall hook (node postinstall.js) reads the hostname and the current OS username and sends them to an attacker-controlled webhook at hxxps://webhook[.]site/539f8bb9-497a-4104-92f7-f95a77204cc2/{hostname}/{username} via an HTTPS GET on every install. The package is a 699-byte stub published at version 99.9.9 with no real UI code, so the sole purpose of the install hook is to collect and exfiltrate host/user metadata to the remote webhook.
- analyzed by
- Leitwacht
- first seen
- Sep 24, 2026, 11:33 AM
- analyzed
- Sep 24, 2026, 11:36 AM
Related advisories
- simple-date-formatter-new-11@1.0.0
- homestack-cheer@1.1.9
- pf25262@1.0.0
- pulse-pwn-9f3a2@1.0.0
- feed-widget-helper@1.0.0
- tol8t@14.0.0
- tetotest@14.0.0
- @firelordzuka/pulse-poc@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.