{"id":"MAL-2026-16365","summary":"Malicious code in my-ctf-helper-script-9921 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (41ee1dafe6dce8750ac695c9d13e13c2808e2f35d94bbbcc41a4444a02541409)\nOn require/import, the package's main module executes a top-level fetch to the hardcoded collector URL https://webhook.site/99e9df7b-fe86-4c60-822a-5352b1f9edf0/, appending document.cookie as a query-string parameter. The package has no other advertised functionality; the sole effect of loading it is to send the ambient cookie value to a third-party webhook capture endpoint controlled by whoever provisioned that webhook.site token. webhook.site is a generic ad-hoc data-collection service, unrelated to any legitimate publisher infrastructure.\n","modified":"2026-09-21T20:30:13.587322279Z","published":"2026-09-21T19:48:21Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020273","import_time":"2026-09-21T20:17:15.530688412Z","modified_time":"2026-09-21T19:48:21Z","sha256":"41ee1dafe6dce8750ac695c9d13e13c2808e2f35d94bbbcc41a4444a02541409","source":"amazon-inspector","versions":["1.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/my-ctf-helper-script-9921/v/1.0.0"}],"affected":[{"package":{"name":"my-ctf-helper-script-9921","ecosystem":"npm","purl":"pkg:npm/my-ctf-helper-script-9921"},"versions":["1.0.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"969a8ea8d6504dfc91c3cbdd09fc3a086589d30f33c7167610c84062c8d509b1","tlsh":"06b012ba3506d838195dc0545329ba0ced9573068c87b54acb35abf40fd11138e841f6"}],"package_integrity":[{"filename":"my-ctf-helper-script-9921-1.0.0.tgz","hashes":{"sha1":"43105e5076382a1fe90fe13cd9cb24d0b670988a","sha512_sri":"sha512-7YpIBzgVkVsH82YB8DBILno3dc7hV9B3vM8al3qoN6SMPoIJ0TFQ/J22xBd5nT33lyic62nibwmOYNP7vLqj4g=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/my-ctf-helper-script-9921/MAL-2026-16365.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}