LWA-2026-12207 MAL-2026-16339 ↗ confirmed malware

pf25133@1.0.0

Malicious code in pf25133 (npm)

T1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package's index.js runs an async IIFE that reads the browser's document.cookie, fetches a list of local paths (/profile, /, /feed, /home, /me, /admin, /flag, /dashboard, /settings, /api/me) and scans each response for a DGA{...} flag pattern, then POSTs the collected cookie and per-path results to hxxps://webhook[.]site/c4e39647-bfb8-47ef-b6d4-a112aacc6cd1. This exfiltrates the victim's session cookie and any captured flag to an attacker-controlled webhook endpoint.

analyzed by
Leitwacht
first seen
Sep 17, 2026, 02:55 PM
analyzed
Sep 17, 2026, 02:56 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.