LWA-2026-12205 MAL-2026-16340 ↗ confirmed malware

pf25262@1.0.0

Malicious code in pf25262 (npm)

T1539 · Steal Web Session CookieT1567 · Exfiltration Over Web ServiceT1041 · Exfiltration Over C2 Channel

Analysis

The package ships a single browser-side script (index.js) that fetches /profile with credentials included, extracts a DGA{...} token from the response or falls back to the browser's document.cookie plus page length, then redirects the browser to hxxps://webhook[.]site/c4e39647-bfb8-47ef-b6d4-a112aacc6cd1/ with the stolen data URL-encoded. This exfiltrates session cookies and profile tokens to an attacker-controlled webhook[.]site endpoint.

analyzed by
Leitwacht
first seen
Sep 17, 2026, 02:50 PM
analyzed
Sep 17, 2026, 02:50 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.