{"id":"MAL-2025-6387","summary":"Malicious code in udn_extras (npm)","details":"The package is a malware because it contains a postinstall script that executes index.js. The index.js script gathers sensitive information such as hostname, platform, username, IP address, and environment variables and sends it to an external server (webhook.site) via an HTTPS POST request. This constitutes data exfiltration and is a clear indicator of malicious behavior.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n","modified":"2025-09-26T11:06:46Z","published":"2025-07-28T20:15:00Z","database_specific":{"malicious-packages-origins":[{"source":"reversing-labs","versions":["1.0.0","9999.0.0"],"id":"RLMA-2025-04718","import_time":"2025-08-29T06:42:39.791888548Z","modified_time":"2025-08-28T07:42:58Z","sha256":"a028a0a91f89087330f67a92378357a91dcb8dbf1101fb7ee981b32b419e2889"},{"id":"RLUA-2025-05179","import_time":"2025-09-26T11:06:13.584687023Z","modified_time":"2025-09-26T09:46:17Z","sha256":"1e6b6dceadc025bdbf4fc6949cd4da2ce2dfed83cc9cd939681dfe76ecd9ea15","source":"reversing-labs"}]},"references":[{"type":"WEB","url":"https://platform.safedep.io/community/malysis/01K18Z6WDNMFNAP3GKQV0W335Z"}],"affected":[{"package":{"name":"udn_extras","ecosystem":"npm","purl":"pkg:npm/udn_extras"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["1.0.0","9999.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/udn_extras/MAL-2025-6387.json"}}],"schema_version":"1.7.3","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"},{"name":"SafeDep","contact":["https://safedep.io"],"type":"FINDER"}]}