MAL-2025-6387

    Dashboard / Malicious Package / MAL-2025-6387

    MAL-2025-6387

    Published: 28 Jul 2025Last Modified: 26 Sept 2025

    Summary: Malicious code in udn_extras (npm)

    Details: The package is a malware because it contains a postinstall script that executes index.js. The index.js script gathers sensitive information such as hostname, platform, username, IP address, and environment variables and sends it to an external server (webhook.site) via an HTTPS POST request. This constitutes data exfiltration and is a clear indicator of malicious behavior.

    Affected packages

    Package

    Name: udn_extras

    Purl: pkg:npm/udn_extras

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    1.0.0
    MAL-2025-6387 | CVE-DB