MAL-2026-16362

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@uh-platform/webcard/MAL-2026-16362.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-16362
Published
2026-09-21T18:56:16Z
Modified
2026-09-21T19:30:05Z
Summary
Malicious code in @uh-platform/webcard (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (2b9f7c250a563ff0915cbcdb1e2fa8a402094c030d7223a726c69ffea6de4b8c)

@uh-platform/webcard@99.0.0 declares a preinstall hook that runs index.js, which shells out to curl against a unique Burp Collaborator subdomain at http://pa33pg1od9cr4ffnrzec8864jvpmdd12.oastify.com/. This fires unconditionally on npm install and confirms code execution and DNS/HTTP callback from the installer's host to an attacker-controlled out-of-band collector. The package version is 99.0.0 under an org scope with a self-referential dependency on @uh-platform/webcard@1.0.2 and a redacted SDK description, matching the canonical dependency-confusion shape aimed at hijacking resolution of an internal scoped package name.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020269",
            "import_time":  "2026-09-21T19:14:59.727304269Z",
            "modified_time":  "2026-09-21T18:56:16Z",
            "sha256":  "2b9f7c250a563ff0915cbcdb1e2fa8a402094c030d7223a726c69ffea6de4b8c",
            "source":  "amazon-inspector",
            "versions":  [
                "99.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @uh-platform/webcard

Package

Name
@uh-platform/webcard
View open source insights on deps.dev
Purl
pkg:npm/%40uh-platform/webcard

Affected ranges

Affected versions

99.*
99.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "index.js",
            "sha256":  "f40ce98f65fd888ee41c09a8a85001c235a2ad90d53b385511bbb4603eb61122",
            "tlsh":  "50e07d0448f9443631629455f91e481e75479801113af14769cf9a101780588c01d2da"
        },
        {
            "path":  "package.json",
            "sha256":  "2135afa924e2083f63eede0736dfd246053430ccc30cdf73897eb21d49c7381c",
            "tlsh":  "e7e086705921a53315d616e288a994576261cf6b0408bc0c67cb143c85ef7b758ff35c"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "webcard-99.0.0.tgz",
            "hashes":  {
                "sha1":  "f149499d40c54b202e46a404cd98397ebc25fc82",
                "sha512_sri":  "sha512-t60sn+FKAAqj+9GlLHbRw0LyAxI7O/stk0NPKBnR+RIzOieuRDR2ZGTs4tSdJDuK63u/3sPksjQWaHltq+pwhQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@uh-platform/webcard/MAL-2026-16362.json"