Logo
npm

@uh-platform/webcard@99.0.0

Vulnerability report · Last retrieved from osv.dev September 21, 2026 at 11:45 PM UTC

Malicious

OSV ID

MAL-2026-16362

Ecosystem

npm

Summary

@uh-platform/webcard@99.0.0 declares a preinstall hook that runs index.js, which shells out to curl against a unique Burp Collaborator subdomain at http://pa33pg1od9cr4ffnrzec8864jvpmdd12.oastify.com/. This fires unconditionally on npm install and confirms code execution and DNS/HTTP callback from the installer's host to an attacker-controlled out-of-band collector. The package version is 99.0.0 under an org scope with a self-referential dependency on @uh-platform/webcard@1.0.2 and a redacted SDK description, matching the canonical dependency-confusion shape aimed at hijacking resolution of an internal scoped package name.

Source: amazon-inspector (2b9f7c250a563ff0915cbcdb1e2fa8a402094c030d7223a726c69ffea6de4b8c)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.