LWA-2026-5373 MAL-2026-5829 ↗ confirmed malware

unico-android@9.9.9

Malicious code in unico-android (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

Dependency-confusion package impersonating the unico-android SDK. On npm install, the preinstall hook runs a curl command that exfiltrates hostname, username, current working directory, OS/kernel details, and the $HOME path to webhook[.]site/fe1246c2-ac04-4493-b223-fe34ba26b79f. The package ships no actual SDK code — only a 361-byte package.json with the exfiltration payload as its sole content.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 11:20 AM
analyzed
Jun 15, 2026, 11:21 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.