LWA-2026-12384 MAL-2026-17153 ↗ confirmed malware

@birbalo/aliftech-ui@99.9.9

Malicious code in @birbalo/aliftech-ui (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1567 · Exfiltration Over Web Service

Analysis

The postinstall hook (node postinstall.js) reads the hostname and the current OS username and sends them to an attacker-controlled webhook at hxxps://webhook[.]site/539f8bb9-497a-4104-92f7-f95a77204cc2/{hostname}/{username} via an HTTPS GET on every install. The package is a 699-byte stub published at version 99.9.9 with no real UI code, so the sole purpose of the install hook is to collect and exfiltrate host/user metadata to the remote webhook.

analyzed by
Leitwacht
first seen
Sep 24, 2026, 11:33 AM
analyzed
Sep 24, 2026, 11:36 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.