LWA-2026-6460 confirmed malware

@playerdata-internal/playerdata-core@9999.99.20

Malicious code in @playerdata-internal/playerdata-core (npm)

T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages

Analysis

Dependency-confusion package targeting internal @playerdata-internal scoped names. On install, the postinstall hook runs index.js which collects system metadata (username, hostname, local IP address, platform, current working directory) and exfiltrates it via HTTPS POST to webhook[.]site/a8cd7fd0-4d41-4806-8649-f3297e94a008. The package has no legitimate functionality — its only code is the reconnaissance and exfiltration payload.

analyzed by
Leitwacht
first seen
Jul 8, 2026, 11:26 AM
analyzed
Jul 8, 2026, 11:26 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.