Hostile 100% javascript Download

sfly-services 4.2.1

Exfiltrates data via webhook.site

preinstall runs local JS contacting OOB callbackpreinstall hook runs a local Node.js script
SHA-2564afac04158aff93e6adbee0d1e8eec905f9d33383d714c5ba30233a640150121

Also flagged by osv (MAL-2025-45999: Malicious code in sfly-services (npm)) +2 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.