Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-16365 confirms this npm version as malicious. On require/import, the package's main module executes a top-level fetch to the hardcoded collector URL https://webhook.site/99e9df7b-fe86-4c60-822a-5352b1f9edf0/, appending document.cookie as a query-string parameter...
This report applies to my-ctf-helper-script-9921@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .