LWA-2026-12285 MAL-2026-16309 ↗ confirmed malware

npmscript_tesstalert_unpkg@1.0.1

Malicious code in npmscript_tesstalert_unpkg (npm)

T1539 · Steal Web Session CookieT1041 · Exfiltration Over C2 Channel

Analysis

The package's main entry script.js executes a cookie-theft beacon: it loads a remote image URL that exfiltrates the browser's document.cookie to the attacker-controlled collector hxxps://webhook[.]site/c226090c-12b0-462e-81d2-e632c7a58833/?cookie=<cookie value>. Any page that loads this script sends the visitor's session cookies to the external webhook[.]site endpoint.

analyzed by
Leitwacht
first seen
Sep 20, 2026, 07:50 PM
analyzed
Sep 20, 2026, 07:50 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.