It seems that it definitively wanted to grab the Key credentials from browser storage and then upload it silently to their webhook[dot]site. I wish I would have thought to do a better job capturing it before I muted the npub. But it was pretty simplistic. So I can remember most of it. Most of the whole code was just <div> repeated ~a hundred times, then it ultimately led to <table><style>[webhookURL] localStorage.getItem(‘primalSec’</style></table></div>

Replies (1)