LWA-2026-5371 MAL-2026-5831 ↗ confirmed malware

unicocheck-ios@9.9.9

Malicious code in unicocheck-ios (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

On npm install, the preinstall hook executes a curl command that sends host system fingerprinting data to a remote webhook endpoint. The payload collects hostname, current username, working directory, OS kernel details (uname -a), and the HOME directory path, transmitting them as HTTP GET parameters to webhook[.]site/fe1246c2-ac04-4493-b223-fe34ba26b79f. The package is a stub — unpacked size 365 bytes — with no actual SDK code despite claiming to be an iOS biometric SDK, and is published at version 9.9.9 to induce dependency resolution over the legitimate package.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 11:20 AM
analyzed
Jun 15, 2026, 11:21 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.