-= Per source details. Do not edit below this line.=-
The package's main file index.js is an IIFE that, when loaded in a browser same-origin context (e.g. via unpkg), reads location.href and document.cookie, fetches authenticated endpoints such as /profile, /admin, /dev, /flag, and /me with credentials:'include', and POSTs the responses along with a matched flag pattern to the hardcoded webhook https://webhook.site/04d98207-c947-4938-9f0c-f92feae051cb/. package.json contains only a 'ctf' description with no author or repository, and the single shipped artifact is this exfiltration payload. Comments in the file describe it as an unpkg-hosted exfil payload.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020134",
"import_time": "2026-09-17T16:20:25.301835386Z",
"modified_time": "2026-09-17T15:33:42Z",
"sha256": "72ce9bca41cb0378952b582d6f115a3bffd2acea4999a90bae5f916428921b64",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "7ec2e6ef5fd7b57b90dabbb8cc3fd86df4d6287b0045862eed730798ec702f67",
"tlsh": "8f3176b313bd24360903e1991b6ff1764537a12bb583d9d0760c62347f8477a0d86af5"
},
{
"path": "package.json",
"sha256": "e78c86af5cc9d90d9adf8ecae854b52029232055674acff834ef95e1c5f93ecb",
"tlsh": "48b092200a20b47320c88ab04e62964a1aa21d2f5244b90817137428a1fdab319f672d"
}
],
"package_integrity": [
{
"filename": "confx1789550882-1.0.0.tgz",
"hashes": {
"sha1": "89385bfabcf0eb382425f94acfd3dc92adf05a5f",
"sha512_sri": "sha512-zsbI/GRgafzgNIWf/QyGZrHJTukh0L4bECKRWPuoGX4zO6VqyXon9SOX07YmgBPKWDTswSYBRwZTcrAcGqIgvw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/confx1789550882/MAL-2026-16260.json"