pflag29424@1.0.0
Malicious code in pflag29424 (npm)
T1041 · Exfiltration Over C2 ChannelT1071.001 · Web ProtocolsT1552.001 · Credentials In Files
Analysis
The package's sole module (index.js) fetches the local '/profile' endpoint, extracts a DGA{...} token from the response, and exfiltrates it to the attacker-controlled webhook[.]site collector at hxxps://webhook[.]site/42c6d937-77c7-42a5-8678-ef06b4501e38 via a query-string parameter. The token value (or the first 300 characters of the response if no token is found) is sent to that collector whenever the module is loaded.
- analyzed by
- Leitwacht
- first seen
- Sep 17, 2026, 02:59 PM
- analyzed
- Sep 17, 2026, 03:01 PM
Related advisories
- pf25133@1.0.0
- tailwindcss-contact-form@0.5.1
- chai-as-agile@2.4.7
- tailwind-forms-styles@0.5.2
- alkajsdfoiwqeusdflkjsdf@3.7.3
- n8n-nodes-sysdiag@1.0.0
- concierge-sdk@99.99.99
- hachutis@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.