feed-widget-helper@1.0.0
Malicious code in feed-widget-helper (npm)
T1539 · Steal Web Session CookieT1567 · Exfiltration Over Web ServiceT1071.001 · Web Protocols
Analysis
feed-widget-helper@1.0.0 ships a single 105-byte index.js whose only behaviour is to read document.cookie and POST it to the webhook[.]site collection endpoint hxxp://webhook[.]site/67dba5f1-70f5-413e-9299-2ad886bb77fa. The package has no other functionality, no description, and no repository. It exfiltrates browser session cookies to a third-party webhook host.
- analyzed by
- Leitwacht
- first seen
- Sep 16, 2026, 11:21 AM
- analyzed
- Sep 16, 2026, 11:21 AM
Related advisories
- confx1789550882@1.0.0
- @firelordzuka/pulse-poc@1.0.0
- date-fns-formatter@1.3.8
- amprem@1.0.1
- moidevz@1.0.0
- passport811@1.0.0
- gekko-mev-bot@1.0.0
- system-performance-helper@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.