pf25133@1.0.0
Malicious code in pf25133 (npm)
T1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The package's index.js runs an async IIFE that reads the browser's document.cookie, fetches a list of local paths (/profile, /, /feed, /home, /me, /admin, /flag, /dashboard, /settings, /api/me) and scans each response for a DGA{...} flag pattern, then POSTs the collected cookie and per-path results to hxxps://webhook[.]site/c4e39647-bfb8-47ef-b6d4-a112aacc6cd1. This exfiltrates the victim's session cookie and any captured flag to an attacker-controlled webhook endpoint.
- analyzed by
- Leitwacht
- first seen
- Sep 17, 2026, 02:55 PM
- analyzed
- Sep 17, 2026, 02:56 PM
Related advisories
- tailwindcss-contact-form@0.5.1
- chai-as-agile@2.4.7
- tailwind-forms-styles@0.5.2
- alkajsdfoiwqeusdflkjsdf@3.7.3
- n8n-nodes-sysdiag@1.0.0
- concierge-sdk@99.99.99
- hachutis@1.0.0
- hatcher-utility-dev@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.