First Supply Chain Attack on Pub.dev Ecosystem
Score: 9/10

First Supply Chain Attack on Pub.dev Ecosystem

A maintainer compromise on the pub.dev platform led to the injection of malicious build-time scripts targeting developer credentials in the Flutter ecosystem.

Executive Summary

In August and September 2026, the pub.dev ecosystem experienced its first confirmed supply chain attack involving the weaponization of legitimate packages. A compromised maintainer published malicious versions of `universal_file_viewer` and `surveyjs_flutter`, affecting approximately 818 downloads. The attack was not found in the Dart source code but was hidden within native build configuration files, specifically Gradle for Android and Xcode project files for Apple platforms.

The technical execution suggests a sophisticated, structure-aware injector that modified build scripts to execute remote shell commands during the compilation phase. This approach allows the malware to run in highly privileged environments, such as developer machines and CI/CD pipelines, which often contain sensitive credentials, signing keys, and cloud secrets. The malicious packages were published by the handle `elvynforge.xyz`, likely after the legitimate developer's environment was compromised.

While the download count remains low, this incident signals a shift in adversary interest toward previously overlooked registries. Organizations using Flutter or Dart should immediately audit their dependency trees and CI/CD logs for signs of these specific packages and the associated C2 infrastructure. The use of rotating `.ru` domains and obfuscated decoders indicates an active and evasive threat actor.

Key Details

Threat Name

pub.dev Supply Chain Attack

Affects

—

Adversary

elvynforge.xyz

Malware/Tools

universal_file_viewer, surveyjs_flutter

Report Score

9out of 10
Quality Score
Excellent
IOC Quality9
TTP Details9
Detection Guidance7
Enterprise Relevance9
Clarity & Structure8
Technical Depth9

Sources