CRITICAL npm Malware

Malicious code in confx1789550882 (npm)

MAL-2026-16260

Published · Modified

Dependency scanning

Check whether confx1789550882 is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Description


__

Source: amazon-inspector (72ce9bca41cb0378952b582d6f115a3bffd2acea4999a90bae5f916428921b64)

The package's main file index.js is an IIFE that, when loaded in a browser same-origin context (e.g. via unpkg), reads location.href and document.cookie, fetches authenticated endpoints such as /profile, /admin, /dev, /flag, and /me with credentials:'include', and POSTs the responses along with a matched flag pattern to the hardcoded webhook https://webhook.site/04d98207-c947-4938-9f0c-f92feae051cb/. package.json contains only a 'ctf' description with no author or repository, and the single shipped artifact is this exfiltration payload. Comments in the file describe it as an unpkg-hosted exfil payload.

Ready to move

Start Securing

Free, no credit card | First findings in minutes