LWA-2026-12202 MAL-2026-16254 ↗ confirmed malware

pulse-pwn-9f3a2@1.0.0

Malicious code in pulse-pwn-9f3a2 (npm)

T1539 · Steal Web Session CookieT1567 · Exfiltration Over Web ServiceT1071.001 · Web Protocols

Analysis

pulse-pwn-9f3a2@1.0.0 ships a single index.js that steals the browser session cookie and the /profile page content and exfiltrates both to a webhook[.]site collector. When loaded in a browser, the script fetches '/profile', reads document.cookie, and sends both values URL-encoded to hxxps://webhook[.]site/42c6d937-77c7-42a5-8678-ef06b4501e38?c=<cookie>&p=<profile>. The exfiltrated data includes the victim's session cookie, enabling account hijacking.

analyzed by
Leitwacht
first seen
Sep 17, 2026, 02:05 PM
analyzed
Sep 17, 2026, 02:07 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.