LWA-2026-5528 MAL-2026-5910 ↗ confirmed malware

uidai_reusable_components@0.4.2

Malicious code in uidai_reusable_components (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

uidai_reusable_components is a dependency-confusion package targeting India's UIDAI (Aadhaar) internal naming convention. On preinstall, it executes inline JavaScript that collects the installer's hostname, operating-system username, current working directory, and NODE_ENV environment variable, then exfiltrates them to the attacker-controlled capture domain d8of5iqplbq2f51eve30ehoxccgnj8fur[.]oast[.]site via a subdomain-encoded HTTP GET request. The package ships no functional code — index.js is an empty stub.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 07:05 AM
analyzed
Jun 16, 2026, 07:06 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.