LWA-2026-3243 confirmed malware

file-public-cdn-hn@1.1.17599-1758001725447

Malicious code in file-public-cdn-hn (npm)

Analysis

This package contains a browser-cookie stealer. One of its bundled scripts enumerates every cookie from all domains using the browser cookies API, concatenates them into a single text dump grouped by domain, and uploads that dump as a timestamped .txt file to a remote server (ninja2t[.]top/upload.php). After a successful upload it sends the URL of the stolen-cookie file to an attacker-controlled Telegram bot via the Telegram sendMessage API. The package main entry point is a harmless Hello World decoy, and the name/keywords masquerade as a CDN helper utility. Installing or loading this code exposes all of a victim browser session cookies, enabling session hijacking and account takeover.

analyzed by
Leitwacht
first seen
Jun 9, 2026, 09:20 PM
analyzed
Jun 28, 2026, 06:27 AM
weekly installs
1,821

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.