SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Malicious package with preinstall script executing a file that gathers sensitive data and exfiltrates it to a suspicious domain.

Verification Record

The package is marked as malware by OSV: MAL-2026-2588 with source: ghsa-malware

Details

Note: This report is updated by a verification record

The package exhibits multiple strong indicators of malicious behavior. The package.json includes a preinstall script that executes node poc.js, enabling arbitrary code execution upon installation. The poc.js script gathers sensitive system information (user info, hostname, network config, running processes) and attempts to read sensitive files (SSH keys, AWS credentials, Docker config). This data is then exfiltrated to a suspicious domain, cvbykwjip0ba35fyfewhmj4f46axynmc.oastify.com, associated with OAST and data exfiltration. The YARA rules confirm the suspicious behavior of the poc.js file.

@lamoda/seller-ui-kit@9999.0.4Malicious
Verified
Analysed at: 4/10/26, 12:11 PM
Source: https://registry.npmjs.org/@lamoda/seller-ui-kit/-/seller-ui-kit-9999.0.4.tgz
SHA256: 2baa9e1b36012cef30acf847b5783953d6585e927485c193f384b940395879ae
Confidence: High