pulse-pwn-9f3a2@1.0.0
Malicious code in pulse-pwn-9f3a2 (npm)
T1539 · Steal Web Session CookieT1567 · Exfiltration Over Web ServiceT1071.001 · Web Protocols
Analysis
pulse-pwn-9f3a2@1.0.0 ships a single index.js that steals the browser session cookie and the /profile page content and exfiltrates both to a webhook[.]site collector. When loaded in a browser, the script fetches '/profile', reads document.cookie, and sends both values URL-encoded to hxxps://webhook[.]site/42c6d937-77c7-42a5-8678-ef06b4501e38?c=<cookie>&p=<profile>. The exfiltrated data includes the victim's session cookie, enabling account hijacking.
- analyzed by
- Leitwacht
- first seen
- Sep 17, 2026, 02:05 PM
- analyzed
- Sep 17, 2026, 02:07 PM
Related advisories
- feed-widget-helper@1.0.0
- confx1789550882@1.0.0
- @firelordzuka/pulse-poc@1.0.0
- date-fns-formatter@1.3.8
- amprem@1.0.1
- moidevz@1.0.0
- passport811@1.0.0
- gekko-mev-bot@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.