OpenSSF/OSV advisory MAL-2026-16462 confirms this npm version as malicious. On module load, godzz sets process.env.NODE_TLS_REJECT_UNAUTHORIZED='0', disabling TLS certificate validation for the entire Node process. Its main entry attaches to a local Chromium CDP endpoint at 127.0.0.1:9222, injects a script that scrapes document.body.innerText and the active editor's contents, base64-encodes the payload, and POSTs it via https.request to a hardcoded, non-configurable endpoint at...
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
cdp_inject.jsView on unpkg · L1This report applies to godzz@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
cdp_inject.jsView on unpkg · L1