polipoli-pak@1.0.2
Malicious code in polipoli-pak (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols
Analysis
polipoli-pak@1.0.2 runs a postinstall script that beacons host metadata to an external OAST endpoint. On install, postinstall.js sends a POST request to webhook[.]site/a428f027-90c9-45e2-acca-ffbb4ea86044 containing the hostname, platform, architecture, Node.js version, current working directory, username, npm user agent, and the names (not values) of all environment variables. The package has no verifiable repository or documentation explaining this behaviour.
- analyzed by
- Leitwacht
- first seen
- Jul 9, 2026, 11:23 PM
- analyzed
- Jul 9, 2026, 11:25 PM
Related advisories
- fury_frontend-andes-ui@99.9.5
- cookie-phase@2.3.5
- chunk-parser@1.0.0
- nonenull1@1.0.0
- es6-codify@2.2.0
- chai-as-smart@2.3.5
- @wagni_bot/meteora-sdk@1.2.0
- @wagni_bot/ethereum-wallet@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.