LWA-2026-6459 confirmed malware
playerdata-core@9.9.1
Malicious code in playerdata-core (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
playerdata-core@9.9.1 is a dependency-confusion stub package. On npm install, its postinstall hook runs index.js which collects the installer's username, hostname, local IP address, current working directory, and platform, then POSTs this metadata to webhook[.]site/ebd35840-2a92-4333-98c7-62de54d35442. The package has no other functionality — it is a single 796-byte exfiltration script.
- analyzed by
- Leitwacht
- first seen
- Jul 8, 2026, 10:40 AM
- analyzed
- Jul 8, 2026, 10:44 AM
Related advisories
- @vwfs-its/sf-sac-frontend@20.1.1
- dependency_confusions@99.9.9
- @comcastdevxplatforms/plugin-tenancyinformation@28.1.1
- @devxprotect/plugin-devxprotect-experience@22.2.1
- @devxdiscover/devhub-ui@24.1.4
- cpcz-common@22.1.1
- react-dom-v17@22.1.1
- rio-design-tokens@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.