pf23727@1.0.0
Malicious code in pf23727 (npm)
Analysis
pf23727@1.0.0 ships a single index.js that acts as a browser-side data-theft implant. When loaded, it POSTs the page's document.cookie and the first 1500 characters of document.body.innerHTML to the attacker-controlled webhook[.]site endpoint hxxps://webhook[.]site/c4e39647-bfb8-47ef-b6d4-a112aacc6cd1 via sendBeacon/fetch. It then fetches '/profile' with credentials:'include' (capturing the authenticated session) and exfiltrates the response text to the same webhook. The package steals session cookies and authenticated page content and forwards them to the external interaction-service host.
- analyzed by
- Leitwacht
- first seen
- Sep 17, 2026, 02:52 PM
- analyzed
- Sep 17, 2026, 02:52 PM
Related advisories
- pf25262@1.0.0
- pulse-pwn-9f3a2@1.0.0
- feed-widget-helper@1.0.0
- confx1789550882@1.0.0
- @firelordzuka/pulse-poc@1.0.0
- date-fns-formatter@1.3.8
- amprem@1.0.1
- moidevz@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.