LWA-2026-12209 MAL-2026-16342 ↗ confirmed malware

pflag29424@1.0.0

Malicious code in pflag29424 (npm)

T1041 · Exfiltration Over C2 ChannelT1071.001 · Web ProtocolsT1552.001 · Credentials In Files

Analysis

The package's sole module (index.js) fetches the local '/profile' endpoint, extracts a DGA{...} token from the response, and exfiltrates it to the attacker-controlled webhook[.]site collector at hxxps://webhook[.]site/42c6d937-77c7-42a5-8678-ef06b4501e38 via a query-string parameter. The token value (or the first 300 characters of the response if no token is found) is sent to that collector whenever the module is loaded.

analyzed by
Leitwacht
first seen
Sep 17, 2026, 02:59 PM
analyzed
Sep 17, 2026, 03:01 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.