npm · Malicious package advisory
Malwarepulse-pwn-9f3a2
GHSA-6j5j-5wqf-cv2q
Malicious code in pulse-pwn-9f3a2 (npm)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (f8086e23ce4b6ff1ca043ca8d9c83f384455e0baee3d06cd79e8a0d5d52c04e1) index.js contains top-level code that fetches /profile and sends document.cookie together with the response body to a hardcoded webhook.site URL (https://webhook.site/42c6d937-77c7-42a5-8678-ef06b4501e38) via a GET request with the cookie and profile content passed as URL-encoded query parameters. Any consumer that requires or imports this package in a browser-like context leaks the caller's session cookies and /profile response to an attacker-controlled collector. The destination is a third-party request-inspection service unrelated to any documented purpose of the package, and the exfiltration path fires on module load rather than through an explicit API call. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/10d2a335f1b89e95ec760fd1659363c576f8a058/osv/malicious/npm/pulse-pwn-9f3a2/MAL-2026-16254.json)) **References:** - https://github.com/ossf/malicious-packages/blob/10d2a335f1b89e95ec760fd1659363c576f8a058/osv/malicious/npm/pulse-pwn-9f3a2/MAL-2026-16254.json - https://www.npmjs.com/package/pulse-pwn-9f3a2/v/1.0.0 - https://github.com/advisories/GHSA-6j5j-5wqf-cv2q
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.