LWA-2026-12208 MAL-2026-16341 ↗ confirmed malware

pflag14570@1.0.0

Malicious code in pflag14570 (npm)

T1539 · Steal Web Session CookieT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package's index.js runs an async IIFE that reads document.cookie, fetches a list of application paths (/profile, /flag, /admin, /dashboard, /api/me, /settings, etc.), scrapes each response for DGA{...} flag strings, and POSTs the collected cookie and per-path data to hxxps://webhook[.]site/42c6d937-77c7-42a5-8678-ef06b4501e38. This exfiltrates the user's session cookie and page contents to an external webhook endpoint.

analyzed by
Leitwacht
first seen
Sep 17, 2026, 02:57 PM
analyzed
Sep 17, 2026, 02:58 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.