getcookiesnpm
getcookies is a confirmed malicious npm package (MAL-2025-21368) that executes malicious code on install. Do not install it — remove it immediately and rotate any exposed credentials.
Malicious code in getcookies (npm)
What this malware does
The package getcookies was found to contain malicious code.
Malicious versions
Every published version of this package is considered malicious — remove it entirely.
Detection & response playbook
Malicious packageFind it
Search your lockfiles and build artifacts for getcookies (all published versions).
If you installed it — respond
Remove getcookies from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.
Did it already run?
If getcookies was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.
Frequently asked questions
Credits
- Amazon Inspector · finder
Detect & block this
O3 blocks getcookies-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.