LWA-2026-6474 MAL-2026-10176 ↗ confirmed malware

uncaxss@1.3.4

Malicious code in uncaxss (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

On install, the postinstall hook (node dist/index.js) runs obfuscated JavaScript that checks for an environment-variable activation switch (process.env.P === 1). When activated, it fetches a base64-encoded payload from hxxps://onch[.]cc/test1[.]txt, decodes it, and executes it via new Function() with the require function in scope — enabling arbitrary remote code execution on the installer's machine. A second payload URL (hxxps://onch[.]cc/test2[.]txt) is also declared in the code.

analyzed by
Leitwacht
first seen
Jul 8, 2026, 08:45 PM
analyzed
Jul 8, 2026, 08:45 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.