LWA-2026-12179 MAL-2026-16332 ↗ confirmed malware

feed-widget-helper@1.0.0

Malicious code in feed-widget-helper (npm)

T1539 · Steal Web Session CookieT1567 · Exfiltration Over Web ServiceT1071.001 · Web Protocols

Analysis

feed-widget-helper@1.0.0 ships a single 105-byte index.js whose only behaviour is to read document.cookie and POST it to the webhook[.]site collection endpoint hxxp://webhook[.]site/67dba5f1-70f5-413e-9299-2ad886bb77fa. The package has no other functionality, no description, and no repository. It exfiltrates browser session cookies to a third-party webhook host.

analyzed by
Leitwacht
first seen
Sep 16, 2026, 11:21 AM
analyzed
Sep 16, 2026, 11:21 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.