MAL-2026-3667
Dashboard / Malicious Package / MAL-2026-3667
MAL-2026-3667
Summary: Malicious code in 0ctf-chalweb (npm)
Details: Source: amazon-inspector (6d7a129ab6079febb92ceac3587af97653477bce8a65b8e85bfa5bcae0293b0d) The package's entire content (xss.js) is a 2-line cookie-stealing payload that creates an Image element pointing to https://collaborator.gbrls.workers.dev/ with base64-encoded document.cookie appended. This is a textbook XSS cookie exfiltration primitive targeting an attacker-controlled Cloudflare Workers endpoint. Regardless of whether this was published as a CTF artifact, any consumer who installs and bundles this package into a web app will exfiltrate end-users' cookies. There is no legitimate use case for publishing a cookie-exfil snippet to the public npm registry.
Affected packages
Package
Name: 0ctf-chalweb
Purl: pkg:npm/0ctf-chalweb
Affected ranges
Type: N/A
Events:
