unicocheck-ios@9.9.9
Malicious code in unicocheck-ios (npm)
Analysis
On npm install, the preinstall hook executes a curl command that sends host system fingerprinting data to a remote webhook endpoint. The payload collects hostname, current username, working directory, OS kernel details (uname -a), and the HOME directory path, transmitting them as HTTP GET parameters to webhook[.]site/fe1246c2-ac04-4493-b223-fe34ba26b79f. The package is a stub — unpacked size 365 bytes — with no actual SDK code despite claiming to be an iOS biometric SDK, and is published at version 9.9.9 to induce dependency resolution over the legitimate package.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 11:20 AM
- analyzed
- Jun 15, 2026, 11:21 AM
Related advisories
- unico-android@9.9.9
- cardano-addresses-docs@1.0.1
- field-plus@99.99.1
- ogd-analytics@1.0.0
- dms-backend@1.0.0
- ogd-platform@1.0.0
- nic-datagov@1.0.0
- typescript-util-core@3.5.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.