VDB
Sign up

MAL-2026-16359

Malicious code in @uh-platform/domain-widget (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (1fa27cef146dec157eaf78519d56ff2ef696f32e99746cdabea9e30be7c03b96) Package @uh-platform/domain-widget@100.0.0 is a scoped placeholder with an empty author, generic description, and no real functionality. Its package.json declares scripts.preinstall = "node index.js", and index.js shells out via exec() to curl a hardcoded Burp Collaborator subdomain at http://pa33pg1od9cr4ffnrzec8864jvpmdd12.oastify.com/. On `npm install`, the installer's host performs a DNS+HTTP request to that attacker-controlled OAST endpoint, disclosing the installer's IP and host presence and confirming out-of-band code execution on the build machine. The `@uh-platform` scope combined with an inflated 100.0.0 version, empty metadata, and a preinstall-only payload is the canonical dependency-confusion shape targeting an internal namespace to shadow a private package during resolution.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@uh-platform/domain-widget

No fixed version published yet for @uh-platform/domain-widget (npm). Pin to a known-safe version or switch to an alternative.

References