uidai_reusable_components@0.4.2
Malicious code in uidai_reusable_components (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
uidai_reusable_components is a dependency-confusion package targeting India's UIDAI (Aadhaar) internal naming convention. On preinstall, it executes inline JavaScript that collects the installer's hostname, operating-system username, current working directory, and NODE_ENV environment variable, then exfiltrates them to the attacker-controlled capture domain d8of5iqplbq2f51eve30ehoxccgnj8fur[.]oast[.]site via a subdomain-encoded HTTP GET request. The package ships no functional code — index.js is an empty stub.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 07:05 AM
- analyzed
- Jun 16, 2026, 07:06 AM
Related advisories
- xboxauthwrapper@3.9.8
- work-planner-client@1.0.0
- workbox-stable-xyz@1.0.0
- wisdomtreetest@1.0.1
- wime-zle@1.1.4
- web-pool@2.3.5
- check-ulid@3.0.2
- web3-deploy-helper@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.