MAL-2025-6387
Dashboard / Malicious Package / MAL-2025-6387
MAL-2025-6387
Published: 28 Jul 2025Last Modified: 26 Sept 2025
Summary: Malicious code in udn_extras (npm)
Details: The package is a malware because it contains a postinstall script that executes index.js. The index.js script gathers sensitive information such as hostname, platform, username, IP address, and environment variables and sends it to an external server (webhook.site) via an HTTPS POST request. This constitutes data exfiltration and is a clear indicator of malicious behavior.
Affected packages
Package
Name: udn_extras
Purl: pkg:npm/udn_extras
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -None
Affected versions
1.0.0
