pf25262@1.0.0
Malicious code in pf25262 (npm)
T1539 · Steal Web Session CookieT1567 · Exfiltration Over Web ServiceT1041 · Exfiltration Over C2 Channel
Analysis
The package ships a single browser-side script (index.js) that fetches /profile with credentials included, extracts a DGA{...} token from the response or falls back to the browser's document.cookie plus page length, then redirects the browser to hxxps://webhook[.]site/c4e39647-bfb8-47ef-b6d4-a112aacc6cd1/ with the stolen data URL-encoded. This exfiltrates session cookies and profile tokens to an attacker-controlled webhook[.]site endpoint.
- analyzed by
- Leitwacht
- first seen
- Sep 17, 2026, 02:50 PM
- analyzed
- Sep 17, 2026, 02:50 PM
Related advisories
- pulse-pwn-9f3a2@1.0.0
- feed-widget-helper@1.0.0
- confx1789550882@1.0.0
- @firelordzuka/pulse-poc@1.0.0
- date-fns-formatter@1.3.8
- amprem@1.0.1
- moidevz@1.0.0
- passport811@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.