LWA-2026-12175 MAL-2026-16260 ↗ confirmed malware

confx1789550882@1.0.0

Malicious code in confx1789550882 (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1539 · Steal Web Session CookieT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

confx1789550882@1.0.0 ships a single index.js that is a browser-context exfiltration payload. When loaded via <script src> it beacons the page's location.href and document.cookie to webhook[.]site/04d98207-c947-4938-9f0c-f92feae051cb/, then fetches authenticated pages (/profile, /admin, /dev, /developer, /flag, /me, /dashboard) with credentials:'include' and exfiltrates up to 3000 characters of each page's HTML to the same endpoint. It also regex-scans the fetched page bodies and cookie for a DGA{...} flag pattern and beacons any match. The payload steals cookies and authenticated page content and sends them to the webhook[.]site collector.

analyzed by
Leitwacht
first seen
Sep 16, 2026, 10:05 AM
analyzed
Sep 16, 2026, 10:10 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.