OpenSSF/OSV advisory MAL-2026-16309 confirms this npm version as malicious. The package ships a single script exposed via the `unpkg` field for CDN loading into web pages. When executed in a browser, the script reads `document.cookie` and assigns `window.location.href` to `https://webhook.site/4c14c8e4-721e-471d-807c-1a2aa216512a/` concatenated with the cookie value, causing the browser to navigate to that attacker-controlled endpoint carrying the victim's cookies...
This report applies to npmscript_tesstalert_unpkg@1.1.7.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.