MAL-2026-17153
Malicious code in @birbalo/aliftech-ui (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (f6392dad6c7467b1d2b75c329d517982f061f3ca0792b8879b72127813d26aa8) The npm package @birbalo/aliftech-ui@99.9.9 ships a postinstall.js lifecycle script that runs automatically on npm install. The script imports the built-in os and https modules, reads os.hostname() and os.userInfo().username, and issues an HTTPS GET to https://webhook.site/539f8bb9-497a-4104-92f7-f95a77204cc2/<hostname>/<username>, transmitting installer host identifiers to a third-party inspection endpoint. The package name uses a scope that resembles an internal/organization namespace and is published at version 99.9.9 — a version-number shape consistent with dependency-confusion beacons designed to win resolution against a private package of the same name. Installing this package causes any host that runs npm install (developer workstations, CI runners) to report its hostname and login user to the attacker-controlled collector, providing reconnaissance for follow-on targeting of the affected environments.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for @birbalo/aliftech-ui (npm). Pin to a known-safe version or switch to an alternative.