MAL-2026-16260

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/confx1789550882/MAL-2026-16260.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-16260
Published
2026-09-17T15:33:42Z
Modified
2026-09-17T16:31:29Z
Summary
Malicious code in confx1789550882 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (72ce9bca41cb0378952b582d6f115a3bffd2acea4999a90bae5f916428921b64)

The package's main file index.js is an IIFE that, when loaded in a browser same-origin context (e.g. via unpkg), reads location.href and document.cookie, fetches authenticated endpoints such as /profile, /admin, /dev, /flag, and /me with credentials:'include', and POSTs the responses along with a matched flag pattern to the hardcoded webhook https://webhook.site/04d98207-c947-4938-9f0c-f92feae051cb/. package.json contains only a 'ctf' description with no author or repository, and the single shipped artifact is this exfiltration payload. Comments in the file describe it as an unpkg-hosted exfil payload.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020134",
            "import_time":  "2026-09-17T16:20:25.301835386Z",
            "modified_time":  "2026-09-17T15:33:42Z",
            "sha256":  "72ce9bca41cb0378952b582d6f115a3bffd2acea4999a90bae5f916428921b64",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / confx1789550882

Package

Name
confx1789550882
View open source insights on deps.dev
Purl
pkg:npm/confx1789550882

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "index.js",
            "sha256":  "7ec2e6ef5fd7b57b90dabbb8cc3fd86df4d6287b0045862eed730798ec702f67",
            "tlsh":  "8f3176b313bd24360903e1991b6ff1764537a12bb583d9d0760c62347f8477a0d86af5"
        },
        {
            "path":  "package.json",
            "sha256":  "e78c86af5cc9d90d9adf8ecae854b52029232055674acff834ef95e1c5f93ecb",
            "tlsh":  "48b092200a20b47320c88ab04e62964a1aa21d2f5244b90817137428a1fdab319f672d"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "confx1789550882-1.0.0.tgz",
            "hashes":  {
                "sha1":  "89385bfabcf0eb382425f94acfd3dc92adf05a5f",
                "sha512_sri":  "sha512-zsbI/GRgafzgNIWf/QyGZrHJTukh0L4bECKRWPuoGX4zO6VqyXon9SOX07YmgBPKWDTswSYBRwZTcrAcGqIgvw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/confx1789550882/MAL-2026-16260.json"