Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-16260 confirms this npm version as malicious. The package's main file index.js is an IIFE that, when loaded in a browser same-origin context (e.g. via unpkg), reads location.href and document.cookie, fetches authenticated endpoints such as /profile, /admin, /dev, /flag, and /me with credentials:'include', and POSTs the responses along with a matched flag pattern to the hardcoded webhook https://webhook.site/04d98207-c947-4938-9f0c-f92feae051cb/. package.json...
This report applies to confx1789550882@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .