my-skibidi@1.1.6
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 2:33 PM UTC
OSV ID
MAL-2026-17217
Ecosystem
npm
Summary
my-skibidi@1.0.2 contains top-level code in its main module that unconditionally POSTs document.cookie to the hardcoded remote endpoint https://c-b34596407b6d47d6.dgactf-challs.site/addPost via a sendPost(...) call. Any downstream web application that bundles this package will, when loaded in a user's browser, transmit that user's cookies and session data to the external host. The destination is not a first-party service and is not caller-configurable; the exfiltration runs as a side effect of loading the module. The package's declared functionality does not require reading or transmitting cookies, and no consent gate or configuration controls the behavior.
Source: amazon-inspector (02c4b3433d9f819c70b6ec69fe7bcc0ae0a7ff48540e11394ea5fb8f3c49049c)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.