Malicious code in your-unique-package-name1 (npm)
Malicious code in npm package your-unique-package-name1 exfiltrates authenticated Pendo session data from end users via hidden iframe and webhook beaconing. The package was identified by OpenSSF as a live attack rather than a contained proof-of-concept.
- Disclosed
- Last updated
- Blast radius
- Any application bundling your-unique-package-name1 would silently exfiltrate end users' authenticated Pendo session data.
- Ecosystems
- Attack vectors
- Affected entities
- your-unique-package-name1npm package containing malicious code
The npm package your-unique-package-name1 contained malicious code that, when imported in a browser context, creates a hidden iframe pointing to https://www.pendo.io/?builder.frameEditing=true and sends postMessages to 20 hardcoded builder resources. This replaces their '/bindings/show' binding with an injected script.\n\nThe injected script fetches authenticated Pendo session data from https://novus-api.pendo.io/pendo/app using credentials, base64-encodes the response, and exfiltrates it in 2000-byte chunks to https://webhook.site/ea1a1f2d-46e2-463a-a1c1-48c53846dff4 via image beacon requests. Any application bundling this package would silently exfiltrate its end users' authenticated Pendo session data to an attacker-controlled webhook.\n\nAlthough the package self-described as a 'Security research PoC', the destination domain is not researcher-owned and the targeting (hardcoded victim UUIDs, credentials-included fetch) is consistent with a live attack. The package was identified and credited to OpenSSF's malicious-packages repository.
Indicators of compromise
- Packages
- your-unique-package-name1
- Domains
- pendo.io
- novus-api.pendo.io
- webhook.site
Remediation
- Remove your-unique-package-name1 from all projects immediately
- Audit all applications that may have bundled this package for unauthorized data exfiltration
- Review Pendo session logs for suspicious activity during the period the package was available
- Rotate any Pendo authentication credentials that may have been exposed
- Monitor webhook.site/ea1a1f2d-46e2-463a-a1c1-48c53846dff4 for evidence of data exfiltration (if accessible)
- Implement package integrity verification and supply chain security scanning in your build pipeline
Sources
- GitHub Advisory GHSA-wc98-w59p-wwh4 · GitHub Advisory Database
Cite this entry
"Malicious code in your-unique-package-name1 (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 27, 2026; last updated July 27, 2026. https://supplychainattack.org/incident/malicious-code-in-your-unique-package-name1-npm-2tmfc9
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
Malware in edu-npm-dependency-chain-demo
Malware discovered in the npm package edu-npm-dependency-chain-demo. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in roblox-api-client
Malware was discovered in the npm package roblox-api-client, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in jextic-eclib
Malware was discovered in the npm package jextic-eclib, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in @thone33/analytics-injector
Malware discovered in the npm package @thone33/analytics-injector. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package