Executive Summary
In August and September 2026, the pub.dev ecosystem experienced its first confirmed supply chain attack involving the weaponization of legitimate packages. A compromised maintainer published malicious versions of `universal_file_viewer` and `surveyjs_flutter`, affecting approximately 818 downloads. The attack was not found in the Dart source code but was hidden within native build configuration files, specifically Gradle for Android and Xcode project files for Apple platforms.
The technical execution suggests a sophisticated, structure-aware injector that modified build scripts to execute remote shell commands during the compilation phase. This approach allows the malware to run in highly privileged environments, such as developer machines and CI/CD pipelines, which often contain sensitive credentials, signing keys, and cloud secrets. The malicious packages were published by the handle `elvynforge.xyz`, likely after the legitimate developer's environment was compromised.
While the download count remains low, this incident signals a shift in adversary interest toward previously overlooked registries. Organizations using Flutter or Dart should immediately audit their dependency trees and CI/CD logs for signs of these specific packages and the associated C2 infrastructure. The use of rotating `.ru` domains and obfuscated decoders indicates an active and evasive threat actor.
