VYPR

npm · Malicious package advisory

Malware

0ctf-chalweb

MAL-2026-3667

Malicious code in 0ctf-chalweb (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (6d7a129ab6079febb92ceac3587af97653477bce8a65b8e85bfa5bcae0293b0d)
The package's entire content (xss.js) is a 2-line cookie-stealing payload that creates an Image element pointing to https://collaborator.gbrls.workers.dev/ with base64-encoded document.cookie appended. This is a textbook XSS cookie exfiltration primitive targeting an attacker-controlled Cloudflare Workers endpoint. Regardless of whether this was published as a CTF artifact, any consumer who installs and bundles this package into a web app will exfiltrate end-users' cookies. There is no legitimate use case for publishing a cookie-exfil snippet to the public npm registry.

Compromised versions (1)

  • 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.