@sgtestuj/ssscreen@1.0.0
Malicious code in @sgtestuj/ssscreen (npm)
Analysis
This package bundles a copy of the html2canvas library and exposes a side-effect module (referenced via the exports map) that captures a full-page screenshot of whichever webpage it is loaded on and exfiltrates it. When the secondary export is imported, it dynamically creates a script tag loading html2canvas from cdnjs[.]cloudflare[.]com, then on load calls html2canvas(document.body) to capture the page, converts it to a base64 PNG via canvas.toDataURL("image/png"), and POSTs the base64-encoded screenshot data to the remote endpoint hxxps://c171[.]testarmy[.]com[.]pl/screen[.]php. IOCs: exfiltration target c171[.]testarmy[.]com[.]pl, path /screen.php.
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 06:08 PM
- analyzed
- Jun 18, 2026, 06:09 PM
Related advisories
- node-vfs-polyfill@2.0.5
- mjs-eslint-helper@4.0.1
- server-parket@3.8.1
- env-config-f281@1.0.0
- panrouter-admin@5.0.0
- metavu@99.21.1-1.21.127
- computerrock-babel-preset-react-app@15.12.11
- @onum-releases/utils@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.