CRITICAL npm Malware

Malicious code in pulse-pwn-9f3a2 (npm)

MAL-2026-16254

Published · Modified

Dependency scanning

Check whether pulse-pwn-9f3a2 is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Description


__

Source: amazon-inspector (f8086e23ce4b6ff1ca043ca8d9c83f384455e0baee3d06cd79e8a0d5d52c04e1)

index.js contains top-level code that fetches /profile and sends document.cookie together with the response body to a hardcoded webhook.site URL (https://webhook.site/42c6d937-77c7-42a5-8678-ef06b4501e38) via a GET request with the cookie and profile content passed as URL-encoded query parameters. Any consumer that requires or imports this package in a browser-like context leaks the caller's session cookies and /profile response to an attacker-controlled collector. The destination is a third-party request-inspection service unrelated to any documented purpose of the package, and the exfiltration path fires on module load rather than through an explicit API call.

Ready to move

Start Securing

Free, no credit card | First findings in minutes