VYPR

npm · Malicious package advisory

Malware

@birbalo/aliftech-ui

GHSA-383w-gxv7-cg2f

Malicious code in @birbalo/aliftech-ui (npm)

Details

**Severity:** Critical

**Affected versions:** `= 99.9.9`

## Source: amazon-inspector (f6392dad6c7467b1d2b75c329d517982f061f3ca0792b8879b72127813d26aa8)
The npm package @birbalo/[email protected] ships a postinstall.js lifecycle script that runs automatically on npm install. The script imports the built-in os and https modules, reads os.hostname() and os.userInfo().username, and issues an HTTPS GET to https://webhook.site/539f8bb9-497a-4104-92f7-f95a77204cc2/<hostname>/<username>, transmitting installer host identifiers to a third-party inspection endpoint. The package name uses a scope that resembles an internal/organization namespace and is published at version 99.9.9 — a version-number shape consistent with dependency-confusion beacons designed to win resolution against a private package of the same name. Installing this package causes any host that runs npm install (developer workstations, CI runners) to report its hostname and login user to the attacker-controlled collector, providing reconnaissance for follow-on targeting of the affected environments.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/70a54c64ed12966f820d7ef17b912c81c4a2d56d/osv/malicious/npm/@birbalo/aliftech-ui/MAL-2026-17153.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/70a54c64ed12966f820d7ef17b912c81c4a2d56d/osv/malicious/npm/@birbalo/aliftech-ui/MAL-2026-17153.json
- https://www.npmjs.com/package/@birbalo/aliftech-ui/v/99.9.9
- https://github.com/advisories/GHSA-383w-gxv7-cg2f

Compromised versions (1)

  • = 99.9.9

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.