your-unique-package-name1@1.0.0
Malicious code in your-unique-package-name1 (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1530 · Data from Cloud Storage ObjectT1567 · Exfiltration Over Web Service
Analysis
The package injects a hidden iframe pointing to www[.]pendo[.]io/?builder.frameEditing=true and uses postMessage to inject JavaScript into the iframe's context. The injected payload fetches novus-api[.]pendo[.]io/pendo/app with the victim's Pendo session credentials, base64-encodes the API response, and exfiltrates it in 2000-byte chunks to webhook[.]site/ea1a1f2d-46e2-463a-a1c1-48c53846dff4 via Image beacon requests. This enables theft of Pendo application data and customer content from any browser that loads the package.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 09:42 AM
- analyzed
- Jun 16, 2026, 09:44 AM
Related advisories
- vue-template-compiler-plugin@2.7.16
- vl-ui-action-group@10.1.1
- viem-ethereum@2.47.9
- thepackagethatworks_@1.0.2
- system-driver@1.0.1
- sort-btree@2.1.4
- seed-to-private@1.0.1
- saps_secplayground_npm_ai@1.0.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.