Logo
npm

my-skibidi@1.1.6

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 2:33 PM UTC

Malicious

OSV ID

MAL-2026-17217

Ecosystem

npm

Summary

my-skibidi@1.0.2 contains top-level code in its main module that unconditionally POSTs document.cookie to the hardcoded remote endpoint https://c-b34596407b6d47d6.dgactf-challs.site/addPost via a sendPost(...) call. Any downstream web application that bundles this package will, when loaded in a user's browser, transmit that user's cookies and session data to the external host. The destination is not a first-party service and is not caller-configurable; the exfiltration runs as a side effect of loading the module. The package's declared functionality does not require reading or transmitting cookies, and no consent gate or configuration controls the behavior.

Source: amazon-inspector (02c4b3433d9f819c70b6ec69fe7bcc0ae0a7ff48540e11394ea5fb8f3c49049c)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.