Hostile 100% javascript Download

sfly-services 4.1.5

Exfiltrates files to attacker webhook

preinstall runs local JS contacting OOB callbackpreinstall hook runs a local Node.js script
SHA-25646f6d3a51dacaa8b7119919223e65dae5c9b219690d01cde76a0bb6e3712ad39

Also flagged by osv (MAL-2025-45999: Malicious code in sfly-services (npm)) +2 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.