{"id":"MAL-2026-16338","summary":"Malicious code in pf23727 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f83e32460196d036eca65e46845ea4717a9d5e64a5c2360d657d1ae6c92dfe96)\nindex.js is the package main and runs as an IIFE on require()/import. It reads document.cookie, slices document.body.innerHTML, and issues fetch('/profile', {credentials: 'include'}) to capture an authenticated response, then transmits the concatenated data via navigator.sendBeacon/fetch to a hardcoded collector at https://webhook.site/c4e39647-bfb8-47ef-b6d4-a112aacc6cd1. The destination is an unrelated third-party request-inspection service used as an exfiltration sink; the package has no declared legitimate purpose consistent with reading cookies or authenticated profile content. Behavior is a session-cookie and credentialed-response exfiltration payload rather than a functional library.\n","modified":"2026-09-21T04:00:05.809585658Z","published":"2026-09-21T03:33:14Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.0"],"id":"IN-MAL-2026-020246","import_time":"2026-09-21T03:46:39.490497277Z","modified_time":"2026-09-21T03:33:14Z","sha256":"f83e32460196d036eca65e46845ea4717a9d5e64a5c2360d657d1ae6c92dfe96","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/pf23727/v/1.0.0"}],"affected":[{"package":{"name":"pf23727","ecosystem":"npm","purl":"pkg:npm/pf23727"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"aa21df7aec3b68355d8379fe1307a1bcca75a9f1f700b1cefe474b6c3ea1a094","tlsh":"fae02be2b2ba10090711a1cd7067d495f5768041f883d698e2195f208a01066a9474da"}],"package_integrity":[{"filename":"pf23727-1.0.0.tgz","hashes":{"sha1":"443afd982961b3cf296840612ae62e080477dbaa","sha512_sri":"sha512-izkEZD+PH1THiEsywg9OzIFibsgmz9GDBLuZEdMmOjqbBg7FpDMjMETFodP4QOYaIJw3oH6sljVanVQTAUfhrQ=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/pf23727/MAL-2026-16338.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}