npm · Malicious package advisory
Malware@uh-platform/domain-widget
GHSA-xh82-8x4m-9w6c
Malicious code in @uh-platform/domain-widget (npm)
Details
**Severity:** Critical **Affected versions:** `= 100.0.0` ## Source: amazon-inspector (1fa27cef146dec157eaf78519d56ff2ef696f32e99746cdabea9e30be7c03b96) Package @uh-platform/[email protected] is a scoped placeholder with an empty author, generic description, and no real functionality. Its package.json declares scripts.preinstall = "node index.js", and index.js shells out via exec() to curl a hardcoded Burp Collaborator subdomain at http://pa33pg1od9cr4ffnrzec8864jvpmdd12.oastify.com/. On `npm install`, the installer's host performs a DNS+HTTP request to that attacker-controlled OAST endpoint, disclosing the installer's IP and host presence and confirming out-of-band code execution on the build machine. The `@uh-platform` scope combined with an inflated 100.0.0 version, empty metadata, and a preinstall-only payload is the canonical dependency-confusion shape targeting an internal namespace to shadow a private package during resolution. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/6926bf8bfadfccf9e5be36eafde008a2b17caf3e/osv/malicious/npm/@uh-platform/domain-widget/MAL-2026-16359.json)) **References:** - https://github.com/ossf/malicious-packages/blob/6926bf8bfadfccf9e5be36eafde008a2b17caf3e/osv/malicious/npm/@uh-platform/domain-widget/MAL-2026-16359.json - https://www.npmjs.com/package/@uh-platform/domain-widget/v/100.0.0 - https://github.com/advisories/GHSA-xh82-8x4m-9w6c
Compromised versions (1)
- = 100.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.