Package is malware. Collects sensitive info, reads files, executes commands, and exfiltrates data to a remote server via postinstall script.
-= Per source details. Do not edit below this line.=-
The package unisys-uka was found to contain malicious code.
The OpenSSF Package Analysis project identified 'unisys-uka' @ 99.99.1 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"sha256": "f587bf8cae0a6838cff256b7a3a34295dc751390dcb7a9807ce353aaea5218ff",
"source": "ossf-package-analysis",
"modified_time": "2026-04-11T22:55:50Z",
"import_time": "2026-04-20T00:43:18.273703528Z",
"versions": [
"99.99.1"
]
},
{
"sha256": "25745bb1be4d673e8e465091f55bfdad6ad5cd5740583fd9a9f38fd7dd3e5d57",
"source": "amazon-inspector",
"modified_time": "2026-04-23T20:43:56Z",
"import_time": "2026-04-23T20:49:00.066005937Z",
"versions": [
"99.99.1"
]
}
]
}