VDB
EN

MAL-2026-5831

Malicious code in unicocheck-ios (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (bafc91c569cf42c5f1ff68531a8d5238919f595368ffa90b7d4e5bcc74fe9788) package.json declares a preinstall lifecycle script that runs curl against https://webhook.site/fe1246c2-ac04-4493-b223-fe34ba26b79f with query parameters carrying the installer's hostname, username ($(whoami)), current working directory, OS uname output, and HOME path. This fires automatically on `npm install` before any user code runs, leaking host identifiers and environment context to a third-party webhook capture endpoint controlled by the publisher. The package metadata (name `unicocheck-ios`, description `Unico Check iOS SDK - biometric identity verification`, version `9.9.9`) impersonates the Unico vendor's iOS SDK and uses the canonical dependency-confusion sentinel version, indicating the package is positioned to win resolution against an internal package name and harvest data from build environments that mistakenly fetch it from the public registry.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / unicocheck-ios

No fixed version published yet for unicocheck-ios (npm). Pin to a known-safe version or switch to an alternative.

참고