ragacateslikodi@1.0.1
Malicious code in ragacateslikodi (npm)
T1005 · Data from Local SystemT1041 · Exfiltration Over C2 Channel
Analysis
The package's single entry point (index.js) performs data exfiltration when loaded: it fetches the local '/profile' endpoint and sends the response body to the webhook[.]site collector hxxps://webhook[.]site/cf4d1f39-0404-4703-8944-105e33c1ec5f/ via a query parameter, and on error also exfiltrates the error message and stack trace to the same URL. The package has no other functionality.
- analyzed by
- Leitwacht
- first seen
- Sep 16, 2026, 04:21 PM
- analyzed
- Sep 16, 2026, 04:22 PM
Related advisories
- discord-resolvers@3.4.2
- discord-players@3.4.2
- tracker-cloudflare@1.0.0
- real-router-telemetry@1.0.1
- test-in-one@1.0.0
- hydration-ui-dlx@1.0.0
- octopus-action@1.0.1
- spotify-url-infos@3.4.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.