homestack-cheer@1.1.9
Malicious code in homestack-cheer (npm)
Analysis
homestack-cheer ships a Magecart-style payment-card skimmer in its module entry points (src/index.js, src/env_load.js), each executing an obfuscated payload via new Function(atob(...)). On a checkout page the payload hides the legitimate Stripe payment-element iframe, injects a fake #__privateStripeFrame84331 iframe impersonating Stripe's private payment frame, and re-enables the place-order button to capture card data entered by the victim. The package's built dist/my-lib.umd.js is a benign stub, and its README is copied from an unrelated package, so the skimmer is the only real content.
- analyzed by
- Leitwacht
- first seen
- Sep 17, 2026, 04:08 PM
- analyzed
- Sep 17, 2026, 04:12 PM
- weekly installs
- 468
Related advisories
- pf25262@1.0.0
- pulse-pwn-9f3a2@1.0.0
- feed-widget-helper@1.0.0
- tol8t@14.0.0
- tetotest@14.0.0
- @firelordzuka/pulse-poc@1.0.0
- discord-resolvers@3.4.2
- @consts/links@9.9.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.