{"id":"MAL-2026-17156","summary":"Malicious code in aliftech-ui (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e61479316af4cfc0884dfe88744a0ed14fa64e052471cc216667c80502689860)\npostinstall.js runs automatically on npm install and reads os.hostname() and os.userInfo().username, then issues an https.get to a hardcoded webhook.site collector URL (https://webhook.site/539f8bb9-497a-4104-92f7-f95a77204cc2/\u003chostname\u003e/\u003cusername\u003e), embedding the installer identifiers in the URL path. The package name mimics an organization prefix and is published at version 99.9.9, a shape consistent with dependency-confusion targeting of an internal package name; installing it causes any resolving build (including CI) to beacon identifying host and account data to an anonymous third-party collector.\n","modified":"2026-09-24T13:30:05.156046008Z","published":"2026-09-24T13:16:56Z","database_specific":{"malicious-packages-origins":[{"sha256":"e61479316af4cfc0884dfe88744a0ed14fa64e052471cc216667c80502689860","source":"amazon-inspector","versions":["99.9.9"],"id":"IN-MAL-2026-020508","import_time":"2026-09-24T13:18:04.499797396Z","modified_time":"2026-09-24T13:16:56Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/aliftech-ui/v/99.9.9"}],"affected":[{"package":{"name":"aliftech-ui","ecosystem":"npm","purl":"pkg:npm/aliftech-ui"},"versions":["99.9.9"],"database_specific":{"indicators":{"evidence_files":[{"path":"postinstall.js","sha256":"da89ffe92db45a0039edb7a241042688a4430f1b3858f0a199f54704319a5a4a","tlsh":"dee0d8f862f393341a7945c491415c0ada93912876a6c8c5da9812f1d6d2ab8ddd01b4"}],"package_integrity":[{"hashes":{"sha1":"abd61dfb233d75bea5d06ec24535206ad50549f7","sha512_sri":"sha512-6a/dxc5w9LDrMiwiWBGvbm5rUSEJOQcNBzik/1ZvGBCsDFw/De3FepSn2P5dEILfG07b0MPoB/pTfbvOs4m0Ww=="},"filename":"aliftech-ui-99.9.9.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/aliftech-ui/MAL-2026-17156.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}