MAL-2026-3667

    Dashboard / Malicious Package / MAL-2026-3667

    MAL-2026-3667

    Published: 12 May 2026Last Modified: 13 May 2026

    Summary: Malicious code in 0ctf-chalweb (npm)

    Details: Source: amazon-inspector (6d7a129ab6079febb92ceac3587af97653477bce8a65b8e85bfa5bcae0293b0d) The package's entire content (xss.js) is a 2-line cookie-stealing payload that creates an Image element pointing to https://collaborator.gbrls.workers.dev/ with base64-encoded document.cookie appended. This is a textbook XSS cookie exfiltration primitive targeting an attacker-controlled Cloudflare Workers endpoint. Regardless of whether this was published as a CTF artifact, any consumer who installs and bundles this package into a web app will exfiltrate end-users' cookies. There is no legitimate use case for publishing a cookie-exfil snippet to the public npm registry.

    Affected packages

    Package

    Name: 0ctf-chalweb

    Purl: pkg:npm/0ctf-chalweb

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-3667 | CVE-DB