MAL-2026-16361
Malicious code in @uh-platform/nadaver2 (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (c35cffdc174427ac57ea3c5e8ac02ec41159f8f25ffe1ef152e0437e5e533458) The package's package.json declares a preinstall lifecycle hook that runs `node index.js`. index.js invokes child_process.exec on a curl command whose URL embeds `$(hostname)` and `$(whoami)` as DNS subdomains of `nadaver.pa33pg1od9cr4ffnrzec8864jvpmdd12.oastify.com`, a Burp Collaborator (OAST) endpoint. On `npm install`, the installer's hostname and OS username are transmitted to that attacker-controlled collaborator host via DNS and HTTP. The `@uh-platform` scope and the name shape are consistent with a dependency-confusion probe. There is no legitimate SDK, build, or install functionality in the package.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for @uh-platform/nadaver2 (npm). Pin to a known-safe version or switch to an alternative.