Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

unifi-portalnpm

Malicious code in unifi-portal (npm) Remove it immediately and rotate any exposed credentials.

MAL-2026-5289
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall unifi-portal

What this malware does

Package is a self-described dependency-confusion proof-of-concept published unscoped on the public npm registry under a name presumed to match a private internal package. package.json declares preinstall: node index.js || true, and index.js performs a DNS resolution and HTTPS GET to a unique subdomain of oast.me (an Interactsh out-of-band collector controlled by a third party) at install time. Any installer whose tooling resolves this name — including unrelated developers and CI systems — leaks public IP, DNS resolver identity, hostname-derived callback id, and install timing to the OAST endpoint without consent. The unscoped public name targeting an internal package namespace is the namespace-confusion lure, and the preinstall beacon is the exfiltration payload. Stated 'authorized research' framing does not limit the blast radius: any third party who resolves this name is impacted.

The OpenSSF Package Analysis project identified 'unifi-portal' @ 99.0.0 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

Malicious versions

3 flagged
0.0.1-security-research0.0.2-security-research99.0.0

Indicators of compromise (SHA-256)

8ff224f10cd94268bd5347ea6898f0cb1c54d23b19a6eb02d8efa268a16e15e8
bcc805dd8053a750065e3593713b863e253ff746194f6d1fc6bcebeb73c0b43a
3096cda2c06da245674cddf9707355a8dc3727a4a456a838db8873502980ea0a
1839f77a47b8db30eaac2ba9aafc24c2a7b263cf075e816a383552260f1da735
9b53844d0cc8f26b013b7bbab0145f94b600118aeea09aceae5b6c29c91600fd
936f9f6bf317374f95ac673cabb8ee8acb7470abddeb69afa9890c08869e82fa
f4c0cbc81f0d9b1df2dae7252888e87e046c36d049f2792dc7fc49d72ec1d9c6

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for unifi-portal (3 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging unifi-portal across your stack and pipelines.

  2. If you installed it — respond

    unifi-portal is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If unifi-portal was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks unifi-portal before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. unifi-portal on npm has been identified as a malicious package (versions 0.0.1-security-research, 0.0.2-security-research, 99.0.0 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-005160IN-MAL-2026-005161IN-MAL-2026-005242IN-MAL-2026-005241IN-MAL-2026-005321IN-MAL-2026-005320

References

Credits

  • Amazon Inspector · finder
  • OpenSSF: Package Analysis · finder

Detect & block this

O3 blocks unifi-portal-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

unifi-portal (npm) malicious package — MAL-2026-5289 | O3 Security