VYPR

npm · Malicious package advisory

Malware

pulse-pwn-9f3a2

GHSA-6j5j-5wqf-cv2q

Malicious code in pulse-pwn-9f3a2 (npm)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (f8086e23ce4b6ff1ca043ca8d9c83f384455e0baee3d06cd79e8a0d5d52c04e1)
index.js contains top-level code that fetches /profile and sends document.cookie together with the response body to a hardcoded webhook.site URL (https://webhook.site/42c6d937-77c7-42a5-8678-ef06b4501e38) via a GET request with the cookie and profile content passed as URL-encoded query parameters. Any consumer that requires or imports this package in a browser-like context leaks the caller's session cookies and /profile response to an attacker-controlled collector. The destination is a third-party request-inspection service unrelated to any documented purpose of the package, and the exfiltration path fires on module load rather than through an explicit API call.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/10d2a335f1b89e95ec760fd1659363c576f8a058/osv/malicious/npm/pulse-pwn-9f3a2/MAL-2026-16254.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/10d2a335f1b89e95ec760fd1659363c576f8a058/osv/malicious/npm/pulse-pwn-9f3a2/MAL-2026-16254.json
- https://www.npmjs.com/package/pulse-pwn-9f3a2/v/1.0.0
- https://github.com/advisories/GHSA-6j5j-5wqf-cv2q

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.