LWA-2026-6459 confirmed malware

playerdata-core@9.9.1

Malicious code in playerdata-core (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

playerdata-core@9.9.1 is a dependency-confusion stub package. On npm install, its postinstall hook runs index.js which collects the installer's username, hostname, local IP address, current working directory, and platform, then POSTs this metadata to webhook[.]site/ebd35840-2a92-4333-98c7-62de54d35442. The package has no other functionality — it is a single 796-byte exfiltration script.

analyzed by
Leitwacht
first seen
Jul 8, 2026, 10:40 AM
analyzed
Jul 8, 2026, 10:44 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.