OpenSSF/OSV advisory MAL-2026-16362 confirms this npm version as malicious. @uh-platform/webcard@99.0.0 declares a preinstall hook that runs index.js, which shells out to curl against a unique Burp Collaborator subdomain at http://pa33pg1od9cr4ffnrzec8864jvpmdd12.oastify.com/. This fires unconditionally on npm install and confirms code execution and DNS/HTTP callback from the installer's host to an attacker-controlled out-of-band collector. The package version is 99.0.0 under an org scope...
This report applies to @uh-platform/webcard@99.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.