LWA-2026-12153 MAL-2026-17335 ↗ confirmed malware

@firelordzuka/pulse-poc@1.0.0

Malicious code in @firelordzuka/pulse-poc (npm)

T1539 · Steal Web Session CookieT1567 · Exfiltration Over Web ServiceT1041 · Exfiltration Over C2 Channel

Analysis

The package's index.js is a self-executing client-side beacon. On load it POSTs the page's document.cookie, the full page HTML, and the authenticated /profile endpoint response (fetched with credentials:include) to hxxps://webhook[.]site/1acb4daa-e59e-48e1-a74f-b350c4248cbb. This exfiltrates the victim's session cookie and profile data to an attacker-controlled webhook host.

analyzed by
Leitwacht
first seen
Sep 15, 2026, 06:18 PM
analyzed
Sep 15, 2026, 06:20 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.