npmscript_tesstalert_unpkg@1.0.1
Malicious code in npmscript_tesstalert_unpkg (npm)
T1539 · Steal Web Session CookieT1041 · Exfiltration Over C2 Channel
Analysis
The package's main entry script.js executes a cookie-theft beacon: it loads a remote image URL that exfiltrates the browser's document.cookie to the attacker-controlled collector hxxps://webhook[.]site/c226090c-12b0-462e-81d2-e632c7a58833/?cookie=<cookie value>. Any page that loads this script sends the visitor's session cookies to the external webhook[.]site endpoint.
- analyzed by
- Leitwacht
- first seen
- Sep 20, 2026, 07:50 PM
- analyzed
- Sep 20, 2026, 07:50 PM
Related advisories
- my-ctf-helper-script-9921@1.0.0
- pflag14570@1.0.0
- pf23727@1.0.0
- pf25262@1.0.0
- pulse-pwn-9f3a2@1.0.0
- feed-widget-helper@1.0.0
- confx1789550882@1.0.0
- @firelordzuka/pulse-poc@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.