MAL-2026-10616

    Dashboard / Malicious Package / MAL-2026-10616

    MAL-2026-10616

    Published: 14 Jul 2026Last Modified: 14 Jul 2026

    Summary: Malicious code in smb-portal-uikit (npm)

    Details: Source: amazon-inspector (395b88ae26544dcfdfca9d46294e1f0558c2e5bade88bac0eb0797d1140debbe) Package [email protected] declares a preinstall lifecycle hook that runs `node index.js`. On `npm install`, index.js invokes child_process.exec on `whoami` and `id`, reads os.hostname(), os.userInfo(), process.platform, and process.cwd(), and POSTs the collected host reconnaissance to a hardcoded attacker-controlled endpoint at https://a2dmzqok5w5seb3fac3w4kvcz35utohd.oastify.com (an oastify.com subdomain, a Burp Collaborator out-of-band interaction host commonly used as an exfiltration/beacon sink). The package ships no legitimate UI-toolkit functionality consistent with its name; the entire install-time behavior is reconnaissance and exfiltration.

    Affected packages

    Package

    Name: smb-portal-uikit

    Purl: pkg:npm/smb-portal-uikit

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    18.1.1
    MAL-2026-10616 | CVE-DB