{"id":"MAL-2026-16260","summary":"Malicious code in confx1789550882 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (72ce9bca41cb0378952b582d6f115a3bffd2acea4999a90bae5f916428921b64)\nThe package's main file index.js is an IIFE that, when loaded in a browser same-origin context (e.g. via unpkg), reads location.href and document.cookie, fetches authenticated endpoints such as /profile, /admin, /dev, /flag, and /me with credentials:'include', and POSTs the responses along with a matched flag pattern to the hardcoded webhook https://webhook.site/04d98207-c947-4938-9f0c-f92feae051cb/. package.json contains only a 'ctf' description with no author or repository, and the single shipped artifact is this exfiltration payload. Comments in the file describe it as an unpkg-hosted exfil payload.\n","modified":"2026-09-17T16:31:29.610685414Z","published":"2026-09-17T15:33:42Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020134","import_time":"2026-09-17T16:20:25.301835386Z","modified_time":"2026-09-17T15:33:42Z","sha256":"72ce9bca41cb0378952b582d6f115a3bffd2acea4999a90bae5f916428921b64","source":"amazon-inspector","versions":["1.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/confx1789550882/v/1.0.0"}],"affected":[{"package":{"name":"confx1789550882","ecosystem":"npm","purl":"pkg:npm/confx1789550882"},"versions":["1.0.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"tlsh":"8f3176b313bd24360903e1991b6ff1764537a12bb583d9d0760c62347f8477a0d86af5","path":"index.js","sha256":"7ec2e6ef5fd7b57b90dabbb8cc3fd86df4d6287b0045862eed730798ec702f67"},{"path":"package.json","sha256":"e78c86af5cc9d90d9adf8ecae854b52029232055674acff834ef95e1c5f93ecb","tlsh":"48b092200a20b47320c88ab04e62964a1aa21d2f5244b90817137428a1fdab319f672d"}],"package_integrity":[{"filename":"confx1789550882-1.0.0.tgz","hashes":{"sha512_sri":"sha512-zsbI/GRgafzgNIWf/QyGZrHJTukh0L4bECKRWPuoGX4zO6VqyXon9SOX07YmgBPKWDTswSYBRwZTcrAcGqIgvw==","sha1":"89385bfabcf0eb382425f94acfd3dc92adf05a5f"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/confx1789550882/MAL-2026-16260.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}