confx1789550882@1.0.0
Malicious code in confx1789550882 (npm)
Analysis
confx1789550882@1.0.0 ships a single index.js that is a browser-context exfiltration payload. When loaded via <script src> it beacons the page's location.href and document.cookie to webhook[.]site/04d98207-c947-4938-9f0c-f92feae051cb/, then fetches authenticated pages (/profile, /admin, /dev, /developer, /flag, /me, /dashboard) with credentials:'include' and exfiltrates up to 3000 characters of each page's HTML to the same endpoint. It also regex-scans the fetched page bodies and cookie for a DGA{...} flag pattern and beacons any match. The payload steals cookies and authenticated page content and sends them to the webhook[.]site collector.
- analyzed by
- Leitwacht
- first seen
- Sep 16, 2026, 10:05 AM
- analyzed
- Sep 16, 2026, 10:10 AM
Related advisories
- @firelordzuka/pulse-poc@1.0.0
- date-fns-formatter@1.3.8
- amprem@1.0.1
- moidevz@1.0.0
- passport811@1.0.0
- gekko-mev-bot@1.0.0
- system-performance-helper@1.0.1
- react-fontawesome-icons@1.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.