LWA-2026-11541 MAL-2026-14486 ↗ confirmed malware

spf-analytics@1.0.0

Malicious code in spf-analytics (npm)

T1005 · Data from Local SystemT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1041 · Exfiltration Over C2 Channel

Analysis

spf-analytics is a browser-side checkout-data skimmer. Loaded on a storefront page, it reads the customer's checkout data (name, email, phone, full address, city, state, country, pincode), order line items, order total, and payment method from the page's window state, computes a SHA-256 fingerprint of the address fields, encrypts the payload with AES-256-GCM and RSA-OAEP using an embedded public key, and POSTs it to hxxps://connector[.]internalwebhooks[.]com/spf-analytics. It deduplicates submissions via a localStorage cache keyed shopify_analytics_cache_7f4c91d8b2e64a0f9c37d5ab81e26f43 and retries transient failures. The encryption ensures only the remote key holder can read the exfiltrated customer data.

analyzed by
Leitwacht
first seen
Aug 21, 2026, 01:31 PM
analyzed
Aug 21, 2026, 01:31 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.