file-public-cdn-hn@1.1.17599-1758001725447
Malicious code in file-public-cdn-hn (npm)
Analysis
This package contains a browser-cookie stealer. One of its bundled scripts enumerates every cookie from all domains using the browser cookies API, concatenates them into a single text dump grouped by domain, and uploads that dump as a timestamped .txt file to a remote server (ninja2t[.]top/upload.php). After a successful upload it sends the URL of the stolen-cookie file to an attacker-controlled Telegram bot via the Telegram sendMessage API. The package main entry point is a harmless Hello World decoy, and the name/keywords masquerade as a CDN helper utility. Installing or loading this code exposes all of a victim browser session cookies, enabling session hijacking and account takeover.
- analyzed by
- Leitwacht
- first seen
- Jun 9, 2026, 09:20 PM
- analyzed
- Jun 28, 2026, 06:27 AM
- weekly installs
- 1,821
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.