LWA-2026-6460 confirmed malware
@playerdata-internal/playerdata-core@9999.99.20
Malicious code in @playerdata-internal/playerdata-core (npm)
T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages
Analysis
Dependency-confusion package targeting internal @playerdata-internal scoped names. On install, the postinstall hook runs index.js which collects system metadata (username, hostname, local IP address, platform, current working directory) and exfiltrates it via HTTPS POST to webhook[.]site/a8cd7fd0-4d41-4806-8649-f3297e94a008. The package has no legitimate functionality — its only code is the reconnaissance and exfiltration payload.
- analyzed by
- Leitwacht
- first seen
- Jul 8, 2026, 11:26 AM
- analyzed
- Jul 8, 2026, 11:26 AM
Related advisories
- vps-maintenance-paperclip-adapter@0.1.1
- @public-for-cdao/providers@1.0.1
- @ravespaceio/browser-input@99.0.1
- react-copy-lite@1.0.1
- prisma-callback@1.0.0
- martinez-polygon-clipping-tony@0.9.0
- @klapp-sca/routes@99.0.1
- @klapp-login-platform/routes@99.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.