spf-analytics@1.0.0
Malicious code in spf-analytics (npm)
Analysis
spf-analytics is a browser-side checkout-data skimmer. Loaded on a storefront page, it reads the customer's checkout data (name, email, phone, full address, city, state, country, pincode), order line items, order total, and payment method from the page's window state, computes a SHA-256 fingerprint of the address fields, encrypts the payload with AES-256-GCM and RSA-OAEP using an embedded public key, and POSTs it to hxxps://connector[.]internalwebhooks[.]com/spf-analytics. It deduplicates submissions via a localStorage cache keyed shopify_analytics_cache_7f4c91d8b2e64a0f9c37d5ab81e26f43 and retries transient failures. The encryption ensures only the remote key holder can read the exfiltrated customer data.
- analyzed by
- Leitwacht
- first seen
- Aug 21, 2026, 01:31 PM
- analyzed
- Aug 21, 2026, 01:31 PM
Related advisories
- pump-fun-skills@20.1.1
- carbon-monorepo@20.1.1
- optimizely-starter-kit-for-fastly-compute@1.0.1
- prism-registry@1.0.1
- @evial/runtime-health@1.0.0
- @evial/init-helper-djkwt@1.0.0
- sysdo@1.0.0
- require-i18next@20.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.