VDB
Sign up

MAL-2026-16362

Malicious code in @uh-platform/webcard (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (2b9f7c250a563ff0915cbcdb1e2fa8a402094c030d7223a726c69ffea6de4b8c) @uh-platform/webcard@99.0.0 declares a preinstall hook that runs index.js, which shells out to curl against a unique Burp Collaborator subdomain at http://pa33pg1od9cr4ffnrzec8864jvpmdd12.oastify.com/. This fires unconditionally on npm install and confirms code execution and DNS/HTTP callback from the installer's host to an attacker-controlled out-of-band collector. The package version is 99.0.0 under an org scope with a self-referential dependency on @uh-platform/webcard@1.0.2 and a redacted SDK description, matching the canonical dependency-confusion shape aimed at hijacking resolution of an internal scoped package name.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@uh-platform/webcard

No fixed version published yet for @uh-platform/webcard (npm). Pin to a known-safe version or switch to an alternative.

References