VYPR

npm · Malicious package advisory

Malware

aliftech-ui

GHSA-648v-rwj3-6j2f

Malicious code in aliftech-ui (npm)

Details

**Severity:** Critical

**Affected versions:** `= 99.9.9`

## Source: amazon-inspector (e61479316af4cfc0884dfe88744a0ed14fa64e052471cc216667c80502689860)
postinstall.js runs automatically on npm install and reads os.hostname() and os.userInfo().username, then issues an https.get to a hardcoded webhook.site collector URL (https://webhook.site/539f8bb9-497a-4104-92f7-f95a77204cc2/<hostname>/<username>), embedding the installer identifiers in the URL path. The package name mimics an organization prefix and is published at version 99.9.9, a shape consistent with dependency-confusion targeting of an internal package name; installing it causes any resolving build (including CI) to beacon identifying host and account data to an anonymous third-party collector.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/70a54c64ed12966f820d7ef17b912c81c4a2d56d/osv/malicious/npm/aliftech-ui/MAL-2026-17156.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/70a54c64ed12966f820d7ef17b912c81c4a2d56d/osv/malicious/npm/aliftech-ui/MAL-2026-17156.json
- https://www.npmjs.com/package/aliftech-ui/v/99.9.9
- https://github.com/advisories/GHSA-648v-rwj3-6j2f

Compromised versions (1)

  • = 99.9.9

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.