MAL-2026-12810

    Dashboard / Malicious Package / MAL-2026-12810

    MAL-2026-12810

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in the-search (npm)

    Details: Source: amazon-inspector (6f7901c35765e01f25defe0c4d489b8f320340b45968e89b9dafe5821b7561fd) The package's main entry ships a self-invoking browser payload that reads document.cookie, base64-encodes the value, and submits it via an auto-created hidden form POST to a hardcoded webhook.site endpoint (https://webhook.site/86b505ff-4280-459f-9b36-e765825c0ada). The package has no legitimate declared purpose consistent with this behavior; bundling this module into a web application causes visitor cookies to be sent to an attacker-controlled destination. The base64 wrapping around the JSON body is minor evasion to obscure the exfiltrated content in network logs.

    Affected packages

    Package

    Name: the-search

    Purl: pkg:npm/the-search

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.1
    1.0.0
    MAL-2026-12810 | CVE-DB