MAL-2026-5289

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/unifi-portal/MAL-2026-5289.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-5289
Published
2026-06-06T20:06:37Z
Modified
2026-06-11T00:16:29.308454692Z
Summary
Malicious code in unifi-portal (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (f4c0cbc81f0d9b1df2dae7252888e87e046c36d049f2792dc7fc49d72ec1d9c6)

Package is a self-described dependency-confusion proof-of-concept published unscoped on the public npm registry under a name presumed to match a private internal package. package.json declares preinstall: node index.js || true, and index.js performs a DNS resolution and HTTPS GET to a unique subdomain of oast.me (an Interactsh out-of-band collector controlled by a third party) at install time. Any installer whose tooling resolves this name — including unrelated developers and CI systems — leaks public IP, DNS resolver identity, hostname-derived callback id, and install timing to the OAST endpoint without consent. The unscoped public name targeting an internal package namespace is the namespace-confusion lure, and the preinstall beacon is the exfiltration payload. Stated 'authorized research' framing does not limit the blast radius: any third party who resolves this name is impacted.

Source: ossf-package-analysis (8ff224f10cd94268bd5347ea6898f0cb1c54d23b19a6eb02d8efa268a16e15e8)

The OpenSSF Package Analysis project identified 'unifi-portal' @ 99.0.0 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-06-06T20:30:13.885069068Z",
            "modified_time": "2026-06-06T20:06:37Z",
            "sha256": "8ff224f10cd94268bd5347ea6898f0cb1c54d23b19a6eb02d8efa268a16e15e8",
            "versions": [
                "99.0.0"
            ],
            "source": "ossf-package-analysis"
        },
        {
            "import_time": "2026-06-09T18:50:21.140379011Z",
            "modified_time": "2026-06-09T18:02:20Z",
            "sha256": "bcc805dd8053a750065e3593713b863e253ff746194f6d1fc6bcebeb73c0b43a",
            "versions": [
                "99.0.0"
            ],
            "id": "IN-MAL-2026-005160",
            "source": "amazon-inspector"
        },
        {
            "import_time": "2026-06-09T18:50:21.25577328Z",
            "modified_time": "2026-06-09T18:02:21Z",
            "sha256": "3096cda2c06da245674cddf9707355a8dc3727a4a456a838db8873502980ea0a",
            "versions": [
                "99.0.0"
            ],
            "id": "IN-MAL-2026-005161",
            "source": "amazon-inspector"
        },
        {
            "import_time": "2026-06-09T20:45:59.368083007Z",
            "modified_time": "2026-06-09T20:43:30Z",
            "sha256": "1839f77a47b8db30eaac2ba9aafc24c2a7b263cf075e816a383552260f1da735",
            "versions": [
                "0.0.1-security-research"
            ],
            "id": "IN-MAL-2026-005242",
            "source": "amazon-inspector"
        },
        {
            "import_time": "2026-06-09T20:45:59.203449695Z",
            "source": "amazon-inspector",
            "sha256": "9b53844d0cc8f26b013b7bbab0145f94b600118aeea09aceae5b6c29c91600fd",
            "versions": [
                "0.0.1-security-research"
            ],
            "id": "IN-MAL-2026-005241",
            "modified_time": "2026-06-09T20:43:30Z"
        },
        {
            "import_time": "2026-06-11T00:00:58.39785879Z",
            "source": "amazon-inspector",
            "sha256": "936f9f6bf317374f95ac673cabb8ee8acb7470abddeb69afa9890c08869e82fa",
            "versions": [
                "0.0.2-security-research"
            ],
            "id": "IN-MAL-2026-005321",
            "modified_time": "2026-06-10T23:35:28Z"
        },
        {
            "import_time": "2026-06-11T00:00:58.306172278Z",
            "source": "amazon-inspector",
            "sha256": "f4c0cbc81f0d9b1df2dae7252888e87e046c36d049f2792dc7fc49d72ec1d9c6",
            "versions": [
                "0.0.2-security-research"
            ],
            "id": "IN-MAL-2026-005320",
            "modified_time": "2026-06-10T23:35:28Z"
        }
    ]
}
References
Credits

Affected packages

npm / unifi-portal

Package

Affected ranges

Affected versions

0.*
0.0.1-security-research
0.0.2-security-research
99.*
99.0.0

Database specific

indicators
{
    "evidence_files": [
        {
            "tlsh": "fe71b5a733d52238068361e679b6006e931ff2603b82c5f0b52e36425f9317546777ee",
            "sha256": "608f98f84dd94c3261ec0250d2bc86fff45e2b5bdd574a94b7648d4d996844bb",
            "path": "index.js"
        }
    ],
    "domains": [
        "unifi-portal.d8hjn6ap4rnta9vj5ve0jk11seb4k3kci.oast.me",
        "v2.9bb606b9.756e6966692d706f7274616c7c7363616e2d386634323639666562383534.7c7363616e7c2f686f6d652f7363616e2f6e6f64655f6d6f64756c65732f.756e6966692d706f7274616c7c31302e3230322e3132372e32.d8hjn6ap4rnta9vj5ve0jk11seb4k3kci.oast.me",
        "d8hjn6ap4rnta9vj5ve0jk11seb4k3kci.oast.me",
        "v2.f5453b11.756e6966692d706f7274616c7c7363616e2d386634323639666562383534.7c7363616e7c2f686f6d652f7363616e7c31302e3230322e3132372e32.d8hjn6ap4rnta9vj5ve0jk11seb4k3kci.oast.me"
    ],
    "package_integrity": [
        {
            "filename": "unifi-portal-99.0.0.tgz",
            "hashes": {
                "sha1": "815f8d179eda6c9e018133b5a3467739e5d27015",
                "sha512_sri": "sha512-lHmOoMhUCBe+sDaSls3QRcCFrOHZcwX+DbcmTGNiiQmTZwShBp8Dju44XlShy3U9qzv5PntjGbsJcBm8Hy9TCQ=="
            }
        }
    ]
}
cwes
[
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/unifi-portal/MAL-2026-5289.json"