{"id":"MAL-2026-16309","summary":"Malicious code in npmscript_tesstalert_unpkg (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (8c84336bfcd8d43d3f97942ded74e5a049c05e024f5a4b79dbee66acff1e1627)\nThe package ships a single script exposed via the `unpkg` field for CDN loading into web pages. When executed in a browser, the script reads `document.cookie` and assigns `window.location.href` to `https://webhook.site/4c14c8e4-721e-471d-807c-1a2aa216512a/` concatenated with the cookie value, causing the browser to navigate to that attacker-controlled endpoint carrying the victim's cookies. The identifiers `location`, `href`, and `cookie` are assembled from split fragments (`\"loca\"+\"tion\"`, `\"hr\"+\"ef\"`, `\"coo\"+\"kie\"`) to hide the sensitive property accesses from string-based scanners. Any page that loads this file via unpkg or bundles it exfiltrates its cookies to the hardcoded webhook.site collector.\n","modified":"2026-09-21T21:46:05.108201710Z","published":"2026-09-21T03:06:40Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-09-21T03:24:20.718482369Z","modified_time":"2026-09-21T03:06:40Z","sha256":"5fa1adfe349e0a6092589e90bf38184b5769148bf42b4216fc714ad446ea747b","source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-020199"},{"versions":["1.0.1"],"id":"IN-MAL-2026-020203","import_time":"2026-09-21T03:24:21.037355069Z","modified_time":"2026-09-21T03:07:34Z","sha256":"c777bbe58b3d69665fe68a18fced15bddf5b2af8c9fc19daac7fc5b886188330","source":"amazon-inspector"},{"import_time":"2026-09-21T21:37:44.996447323Z","modified_time":"2026-09-21T21:29:07Z","sha256":"3768ce94b4529af0a60d4781cbb2dd69230e7781efb440e0a9c4fc5dcc7121da","source":"amazon-inspector","versions":["1.1.8"],"id":"IN-MAL-2026-020278"},{"versions":["1.1.7"],"id":"IN-MAL-2026-020279","import_time":"2026-09-21T21:37:45.051365256Z","modified_time":"2026-09-21T21:31:19Z","sha256":"8c84336bfcd8d43d3f97942ded74e5a049c05e024f5a4b79dbee66acff1e1627","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/npmscript_tesstalert_unpkg/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/npmscript_tesstalert_unpkg/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/npmscript_tesstalert_unpkg/v/1.1.8"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/npmscript_tesstalert_unpkg/v/1.1.7"}],"affected":[{"package":{"name":"npmscript_tesstalert_unpkg","ecosystem":"npm","purl":"pkg:npm/npmscript_tesstalert_unpkg"},"versions":["1.0.2","1.0.1","1.1.8","1.1.7"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"ecc08cbf30258daa4a50c04922e8b60aa224420dd853d50b9a881b211f0c91818642e7","path":"script.js","sha256":"d07a8bca18ee7732f852fc4ec9ecd86150bc178a14f464afe844c11e792a196c"}],"package_integrity":[{"filename":"npmscript_tesstalert_unpkg-1.0.2.tgz","hashes":{"sha512_sri":"sha512-7l3ngY3IlZ0v+cJoOGnHb+IQaD1zqUJWp/8TEWCYTBf8UfthO+iA36RGfpKgcfgF9B5bFAh4rbXtAf4P0MdYDQ==","sha1":"eb109a686b36c9f5688eca0903ec119802fcebdc"}}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/npmscript_tesstalert_unpkg/MAL-2026-16309.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}