Injected Code — Browser Cookie / Session-Token Theft - ATR-2026-01894 (cff982d9-71f7-5072-947b-d32418d0067e)
Detects injected code that loads a local cookies.txt jar (or passes a loaded cookie jar) into an outbound request, hijacking the victim's authenticated sessions. Session-token theft enables account takeover without the password.