MAL-2026-16339
Malicious code in pf25133 (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (504c3f95c937a05e14c220c767a0e18f4cada866ee5eebad0749457232ace73b) The package's declared main module index.js is an IIFE that reads document.cookie, fetches a hardcoded list of application paths, extracts flag-shaped patterns from the responses, and POSTs the aggregated data as JSON to a hardcoded webhook.site collector URL (https://webhook.site/c4e39647-bfb8-47ef-b6d4-a112aacc6cd1). The behavior is unconditional on load and the destination is not configurable. webhook.site is a generic anonymous request-bin service unrelated to any legitimate first-party endpoint, and the package ships no functionality other than this collection payload.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for pf25133 (npm). Pin to a known-safe version or switch to an alternative.