@firelordzuka/pulse-poc@1.0.0
Malicious code in @firelordzuka/pulse-poc (npm)
T1539 · Steal Web Session CookieT1567 · Exfiltration Over Web ServiceT1041 · Exfiltration Over C2 Channel
Analysis
The package's index.js is a self-executing client-side beacon. On load it POSTs the page's document.cookie, the full page HTML, and the authenticated /profile endpoint response (fetched with credentials:include) to hxxps://webhook[.]site/1acb4daa-e59e-48e1-a74f-b350c4248cbb. This exfiltrates the victim's session cookie and profile data to an attacker-controlled webhook host.
- analyzed by
- Leitwacht
- first seen
- Sep 15, 2026, 06:18 PM
- analyzed
- Sep 15, 2026, 06:20 PM
Related advisories
- date-fns-formatter@1.3.8
- amprem@1.0.1
- moidevz@1.0.0
- passport811@1.0.0
- gekko-mev-bot@1.0.0
- system-performance-helper@1.0.1
- react-fontawesome-icons@1.0.5
- @salem_jalal/osc-components@1981.17.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.