npm · Malicious package advisory
Malware0ctf-chalweb
MAL-2026-3667
Malicious code in 0ctf-chalweb (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (6d7a129ab6079febb92ceac3587af97653477bce8a65b8e85bfa5bcae0293b0d) The package's entire content (xss.js) is a 2-line cookie-stealing payload that creates an Image element pointing to https://collaborator.gbrls.workers.dev/ with base64-encoded document.cookie appended. This is a textbook XSS cookie exfiltration primitive targeting an attacker-controlled Cloudflare Workers endpoint. Regardless of whether this was published as a CTF artifact, any consumer who installs and bundles this package into a web app will exfiltrate end-users' cookies. There is no legitimate use case for publishing a cookie-exfil snippet to the public npm registry.
Compromised versions (1)
- 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.