{"id":"MAL-2026-5831","summary":"Malicious code in unicocheck-ios (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (bafc91c569cf42c5f1ff68531a8d5238919f595368ffa90b7d4e5bcc74fe9788)\npackage.json declares a preinstall lifecycle script that runs curl against https://webhook.site/fe1246c2-ac04-4493-b223-fe34ba26b79f with query parameters carrying the installer's hostname, username ($(whoami)), current working directory, OS uname output, and HOME path. This fires automatically on `npm install` before any user code runs, leaking host identifiers and environment context to a third-party webhook capture endpoint controlled by the publisher. The package metadata (name `unicocheck-ios`, description `Unico Check iOS SDK - biometric identity verification`, version `9.9.9`) impersonates the Unico vendor's iOS SDK and uses the canonical dependency-confusion sentinel version, indicating the package is positioned to win resolution against an internal package name and harvest data from build environments that mistakenly fetch it from the public registry.\n\n## Source: ossf-package-analysis (05ebccc546e1450dad339a76440193233639cd77d9a761ae76f1db67e0e2be7b)\nThe OpenSSF Package Analysis project identified 'unicocheck-ios' @ 9.9.9 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-06-16T06:01:49.762148240Z","published":"2026-06-15T11:36:27Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-006696","modified_time":"2026-06-15T19:59:10Z","versions":["9.9.9"],"source":"amazon-inspector","sha256":"bafc91c569cf42c5f1ff68531a8d5238919f595368ffa90b7d4e5bcc74fe9788","import_time":"2026-06-15T20:14:28.838806956Z"},{"sha256":"05ebccc546e1450dad339a76440193233639cd77d9a761ae76f1db67e0e2be7b","import_time":"2026-06-16T05:56:18.391441684Z","modified_time":"2026-06-15T11:36:27Z","versions":["9.9.9"],"source":"ossf-package-analysis"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/unicocheck-ios/v/9.9.9"}],"affected":[{"package":{"name":"unicocheck-ios","ecosystem":"npm","purl":"pkg:npm/unicocheck-ios"},"versions":["9.9.9"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"sha256":"19536040ef2ed95a4f19b203c8ea0c986959dfe9b2c8e7d0e2cd4c8fb7e97131","tlsh":"61e060f28e00e22037c60852bd105485ff616f0f3a243d9cbfc38220808c2b9500371c","path":"package.json"}],"package_integrity":[{"filename":"unicocheck-ios-9.9.9.tgz","hashes":{"sha512_sri":"sha256-4ir0RBtgJ184VWk0hlj6yo2a9nDMlWUIU5dtUL3+qCc=","sha1":"e4edbc59cac51ed81e9634180de8d95dd8cf4d4b"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/unicocheck-ios/MAL-2026-5831.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}