clover-codelab-remote-pay-cloud@99.9.9
Malicious code in clover-codelab-remote-pay-cloud (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
The package is a combosquat of the Clover payment platform name, published at version 99.9.9. Its postinstall hook runs index.js, which collects the installer's username, hostname, local IP address, and current working directory, then sends this data as a JSON POST to webhook[.]site/9aa13631-fbb0-4b6b-a256-27d1672f767c. The webhook[.]site service is a third-party HTTP request collector commonly abused for data exfiltration. No credentials or tokens are stolen, but the package silently exfiltrates system-identifying information on install.
- analyzed by
- Leitwacht
- first seen
- Jul 17, 2026, 04:05 PM
- analyzed
- Jul 17, 2026, 04:05 PM
Related advisories
- og-boost-br@1.0.0
- crypto-javas@2.0.8
- n8n-nodes-http-probe@1.0.0
- n8n-nodes-probe@1.0.0
- n8n-nodes-port-scanner@1.0.0
- n8n-nodes-net-utils@1.0.0
- n8n-nodes-utils-helper@1.0.0
- n8n-nodes-task-runner@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.