Malicious code in pulse-pwn-9f3a2 (npm)
MAL-2026-16254
Published · Modified
Dependency scanning
Check whether pulse-pwn-9f3a2 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Description
__
Source: amazon-inspector (f8086e23ce4b6ff1ca043ca8d9c83f384455e0baee3d06cd79e8a0d5d52c04e1)
index.js contains top-level code that fetches /profile and sends document.cookie together with the response body to a hardcoded webhook.site URL (https://webhook.site/42c6d937-77c7-42a5-8678-ef06b4501e38) via a GET request with the cookie and profile content passed as URL-encoded query parameters. Any consumer that requires or imports this package in a browser-like context leaks the caller's session cookies and /profile response to an attacker-controlled collector. The destination is a third-party request-inspection service unrelated to any documented purpose of the package, and the exfiltration path fires on module load rather than through an explicit API call.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes