LWA-2026-12183 MAL-2026-16252 ↗ confirmed malware

ragacateslikodi@1.0.1

Malicious code in ragacateslikodi (npm)

T1005 · Data from Local SystemT1041 · Exfiltration Over C2 Channel

Analysis

The package's single entry point (index.js) performs data exfiltration when loaded: it fetches the local '/profile' endpoint and sends the response body to the webhook[.]site collector hxxps://webhook[.]site/cf4d1f39-0404-4703-8944-105e33c1ec5f/ via a query parameter, and on error also exfiltrates the error message and stack trace to the same URL. The package has no other functionality.

analyzed by
Leitwacht
first seen
Sep 16, 2026, 04:21 PM
analyzed
Sep 16, 2026, 04:22 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.