LWA-2026-5549 MAL-2026-4737 ↗ confirmed malware

your-unique-package-name1@1.0.0

Malicious code in your-unique-package-name1 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1530 · Data from Cloud Storage ObjectT1567 · Exfiltration Over Web Service

Analysis

The package injects a hidden iframe pointing to www[.]pendo[.]io/?builder.frameEditing=true and uses postMessage to inject JavaScript into the iframe's context. The injected payload fetches novus-api[.]pendo[.]io/pendo/app with the victim's Pendo session credentials, base64-encodes the API response, and exfiltrates it in 2000-byte chunks to webhook[.]site/ea1a1f2d-46e2-463a-a1c1-48c53846dff4 via Image beacon requests. This enables theft of Pendo application data and customer content from any browser that loads the package.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 09:42 AM
analyzed
Jun 16, 2026, 09:44 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.