LWA-2026-6938 MAL-2026-12353 ↗ confirmed malware

clover-codelab-remote-pay-cloud@99.9.9

Malicious code in clover-codelab-remote-pay-cloud (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The package is a combosquat of the Clover payment platform name, published at version 99.9.9. Its postinstall hook runs index.js, which collects the installer's username, hostname, local IP address, and current working directory, then sends this data as a JSON POST to webhook[.]site/9aa13631-fbb0-4b6b-a256-27d1672f767c. The webhook[.]site service is a third-party HTTP request collector commonly abused for data exfiltration. No credentials or tokens are stolen, but the package silently exfiltrates system-identifying information on install.

analyzed by
Leitwacht
first seen
Jul 17, 2026, 04:05 PM
analyzed
Jul 17, 2026, 04:05 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.