unico-android@9.9.9
Malicious code in unico-android (npm)
T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
Dependency-confusion package impersonating the unico-android SDK. On npm install, the preinstall hook runs a curl command that exfiltrates hostname, username, current working directory, OS/kernel details, and the $HOME path to webhook[.]site/fe1246c2-ac04-4493-b223-fe34ba26b79f. The package ships no actual SDK code — only a 361-byte package.json with the exfiltration payload as its sole content.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 11:20 AM
- analyzed
- Jun 15, 2026, 11:21 AM
Related advisories
- field-plus@99.99.1
- ugent_uws@10.9.11
- ogd-analytics@1.0.0
- nic-datagov@1.0.0
- ts-enum-helper@1.0.0
- tether-base@99.0.0
- tecken@0.1.10
- electron-internal-utils@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.