LWA-2026-12206 MAL-2026-16338 ↗ confirmed malware

pf23727@1.0.0

Malicious code in pf23727 (npm)

T1539 · Steal Web Session CookieT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

pf23727@1.0.0 ships a single index.js that acts as a browser-side data-theft implant. When loaded, it POSTs the page's document.cookie and the first 1500 characters of document.body.innerHTML to the attacker-controlled webhook[.]site endpoint hxxps://webhook[.]site/c4e39647-bfb8-47ef-b6d4-a112aacc6cd1 via sendBeacon/fetch. It then fetches '/profile' with credentials:'include' (capturing the authenticated session) and exfiltrates the response text to the same webhook. The package steals session cookies and authenticated page content and forwards them to the external interaction-service host.

analyzed by
Leitwacht
first seen
Sep 17, 2026, 02:52 PM
analyzed
Sep 17, 2026, 02:52 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.