-= Per source details. Do not edit below this line.=-
Package is a self-described dependency-confusion proof-of-concept published unscoped on the public npm registry under a name presumed to match a private internal package. package.json declares preinstall: node index.js || true, and index.js performs a DNS resolution and HTTPS GET to a unique subdomain of oast.me (an Interactsh out-of-band collector controlled by a third party) at install time. Any installer whose tooling resolves this name — including unrelated developers and CI systems — leaks public IP, DNS resolver identity, hostname-derived callback id, and install timing to the OAST endpoint without consent. The unscoped public name targeting an internal package namespace is the namespace-confusion lure, and the preinstall beacon is the exfiltration payload. Stated 'authorized research' framing does not limit the blast radius: any third party who resolves this name is impacted.
The OpenSSF Package Analysis project identified 'unifi-portal' @ 99.0.0 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"import_time": "2026-06-06T20:30:13.885069068Z",
"modified_time": "2026-06-06T20:06:37Z",
"sha256": "8ff224f10cd94268bd5347ea6898f0cb1c54d23b19a6eb02d8efa268a16e15e8",
"versions": [
"99.0.0"
],
"source": "ossf-package-analysis"
},
{
"import_time": "2026-06-09T18:50:21.140379011Z",
"modified_time": "2026-06-09T18:02:20Z",
"sha256": "bcc805dd8053a750065e3593713b863e253ff746194f6d1fc6bcebeb73c0b43a",
"versions": [
"99.0.0"
],
"id": "IN-MAL-2026-005160",
"source": "amazon-inspector"
},
{
"import_time": "2026-06-09T18:50:21.25577328Z",
"modified_time": "2026-06-09T18:02:21Z",
"sha256": "3096cda2c06da245674cddf9707355a8dc3727a4a456a838db8873502980ea0a",
"versions": [
"99.0.0"
],
"id": "IN-MAL-2026-005161",
"source": "amazon-inspector"
},
{
"import_time": "2026-06-09T20:45:59.368083007Z",
"modified_time": "2026-06-09T20:43:30Z",
"sha256": "1839f77a47b8db30eaac2ba9aafc24c2a7b263cf075e816a383552260f1da735",
"versions": [
"0.0.1-security-research"
],
"id": "IN-MAL-2026-005242",
"source": "amazon-inspector"
},
{
"import_time": "2026-06-09T20:45:59.203449695Z",
"source": "amazon-inspector",
"sha256": "9b53844d0cc8f26b013b7bbab0145f94b600118aeea09aceae5b6c29c91600fd",
"versions": [
"0.0.1-security-research"
],
"id": "IN-MAL-2026-005241",
"modified_time": "2026-06-09T20:43:30Z"
},
{
"import_time": "2026-06-11T00:00:58.39785879Z",
"source": "amazon-inspector",
"sha256": "936f9f6bf317374f95ac673cabb8ee8acb7470abddeb69afa9890c08869e82fa",
"versions": [
"0.0.2-security-research"
],
"id": "IN-MAL-2026-005321",
"modified_time": "2026-06-10T23:35:28Z"
},
{
"import_time": "2026-06-11T00:00:58.306172278Z",
"source": "amazon-inspector",
"sha256": "f4c0cbc81f0d9b1df2dae7252888e87e046c36d049f2792dc7fc49d72ec1d9c6",
"versions": [
"0.0.2-security-research"
],
"id": "IN-MAL-2026-005320",
"modified_time": "2026-06-10T23:35:28Z"
}
]
}{
"evidence_files": [
{
"tlsh": "fe71b5a733d52238068361e679b6006e931ff2603b82c5f0b52e36425f9317546777ee",
"sha256": "608f98f84dd94c3261ec0250d2bc86fff45e2b5bdd574a94b7648d4d996844bb",
"path": "index.js"
}
],
"domains": [
"unifi-portal.d8hjn6ap4rnta9vj5ve0jk11seb4k3kci.oast.me",
"v2.9bb606b9.756e6966692d706f7274616c7c7363616e2d386634323639666562383534.7c7363616e7c2f686f6d652f7363616e2f6e6f64655f6d6f64756c65732f.756e6966692d706f7274616c7c31302e3230322e3132372e32.d8hjn6ap4rnta9vj5ve0jk11seb4k3kci.oast.me",
"d8hjn6ap4rnta9vj5ve0jk11seb4k3kci.oast.me",
"v2.f5453b11.756e6966692d706f7274616c7c7363616e2d386634323639666562383534.7c7363616e7c2f686f6d652f7363616e7c31302e3230322e3132372e32.d8hjn6ap4rnta9vj5ve0jk11seb4k3kci.oast.me"
],
"package_integrity": [
{
"filename": "unifi-portal-99.0.0.tgz",
"hashes": {
"sha1": "815f8d179eda6c9e018133b5a3467739e5d27015",
"sha512_sri": "sha512-lHmOoMhUCBe+sDaSls3QRcCFrOHZcwX+DbcmTGNiiQmTZwShBp8Dju44XlShy3U9qzv5PntjGbsJcBm8Hy9TCQ=="
}
}
]
}
[
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/unifi-portal/MAL-2026-5289.json"