OpenSSF/OSV advisory MAL-2026-17153 confirms this npm version as malicious. The npm package @birbalo/aliftech-ui@99.9.9 ships a postinstall.js lifecycle script that runs automatically on npm install. The script imports the built-in os and https modules, reads os.hostname() and os.userInfo().username, and issues an HTTPS GET to https://webhook.site/539f8bb9-497a-4104-92f7-f95a77204cc2/<hostname>/<username>, transmitting installer host identifiers to a third-party inspection endpoint...
This report applies to @birbalo/aliftech-ui@99.9.9.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.