LWA-2026-5372 MAL-2026-5830 ↗ confirmed malware

unico-check@9.9.9

Malicious code in unico-check (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

unico-check@9.9.9 is a dependency-confusion/typosquat package containing a preinstall script that exfiltrates host system information. On install, the hook runs: curl to hxxps://webhook[.]site/fe1246c2-ac04-4493-b223-fe34ba26b79f?pkg=unico-check with query parameters capturing $(hostname), $(whoami), $(pwd), $(uname -a), and $HOME. This system reconnaissance data is sent to an external callback endpoint, enabling the attacker to profile victims for follow-on exploitation.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 11:20 AM
analyzed
Jun 15, 2026, 11:21 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.