LWA-2026-6577 MAL-2026-10099 ↗ confirmed malware

polipoli-pak@1.0.2

Malicious code in polipoli-pak (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols

Analysis

polipoli-pak@1.0.2 runs a postinstall script that beacons host metadata to an external OAST endpoint. On install, postinstall.js sends a POST request to webhook[.]site/a428f027-90c9-45e2-acca-ffbb4ea86044 containing the hostname, platform, architecture, Node.js version, current working directory, username, npm user agent, and the names (not values) of all environment variables. The package has no verifiable repository or documentation explaining this behaviour.

analyzed by
Leitwacht
first seen
Jul 9, 2026, 11:23 PM
analyzed
Jul 9, 2026, 11:25 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.