Hostile 100% javascript Download

sfly-services 4.1.1

Exfiltrates data via webhook.site

preinstall runs local JS contacting OOB callbackpreinstall hook runs a local Node.js script
SHA-256aa4dc3d2e972c8ec0dceca060016bbf018dcaa3f56f7134046ccb89a706fedf6

Also flagged by osv (MAL-2025-45999: Malicious code in sfly-services (npm)) +2 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.