Threats Tagged 'mal-2026-16309'
View all threats tagged with 'mal-2026-16309'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-16309'
Click on any threat for detailed analysis and mitigation recommendations
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (8c84336bfcd8d43d3f97942ded74e5a049c05e024f5a4b79dbee66acff1e1627) The package ships a single script exposed via the `unpkg` field for CDN loading into web pages. When executed in a browser, the script reads `document.cookie` and assigns `window.location.href` to `https://webhook.site/4c14c8e4-721e-471d-807c-1a2aa216512a/` concatenated with the cookie value, causing the browser to navigate to that attacker-controlled endpoint carrying the victim's cookies. The identifiers `location`, `href`, and `cookie` are assembled from split fragments (`"loca"+"tion"`, `"hr"+"ef"`, `"coo"+"kie"`) to hide the sensitive property accesses from string-based scanners. Any page that loads this file via unpkg or bundles it exfiltrates its cookies to the hardcoded webhook.site collector. Join the discussion | GCVE Database | 09/21/2026, 03:06:40 UTC Added: 09/22/2026, 02:04:06 UTC |
Showing 1 to 1 of 1 result