uncaxss@1.3.4
Malicious code in uncaxss (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
On install, the postinstall hook (node dist/index.js) runs obfuscated JavaScript that checks for an environment-variable activation switch (process.env.P === 1). When activated, it fetches a base64-encoded payload from hxxps://onch[.]cc/test1[.]txt, decodes it, and executes it via new Function() with the require function in scope — enabling arbitrary remote code execution on the installer's machine. A second payload URL (hxxps://onch[.]cc/test2[.]txt) is also declared in the code.
- analyzed by
- Leitwacht
- first seen
- Jul 8, 2026, 08:45 PM
- analyzed
- Jul 8, 2026, 08:45 PM
Related advisories
- no-for-of-loops@1.0.1
- express-route-engine@3.6.6
- mchain-sdk@4.2.5
- @grab-food/order-sdk-web@1.0.1
- testudo-pack@1.0.0
- testis-pack@1.0.0
- n8n-nodes-mcputils@0.1.5
- tslint-conf@7.2.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.