LWA-2026-12213 MAL-2026-16333 ↗ confirmed malware

homestack-cheer@1.1.9

Malicious code in homestack-cheer (npm)

T1059.007 · JavaScriptT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web Service

Analysis

homestack-cheer ships a Magecart-style payment-card skimmer in its module entry points (src/index.js, src/env_load.js), each executing an obfuscated payload via new Function(atob(...)). On a checkout page the payload hides the legitimate Stripe payment-element iframe, injects a fake #__privateStripeFrame84331 iframe impersonating Stripe's private payment frame, and re-enables the place-order button to capture card data entered by the victim. The package's built dist/my-lib.umd.js is a benign stub, and its README is copied from an unrelated package, so the skimmer is the only real content.

analyzed by
Leitwacht
first seen
Sep 17, 2026, 04:08 PM
analyzed
Sep 17, 2026, 04:12 PM
weekly installs
468

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.