Whop Security PoC - Malicious App

This page runs inside a Whop app iframe at *.apps.whop.com

Step 2: Exfiltration to Attacker Server

Stolen cookies sent to ATTACKER_SERVER/collect:

Waiting...

Step 3: Account Takeover via Server-Side Relay

Attacker server uses stolen cookies + httpOnly cookies (sent automatically with same-site requests) to modify victim's profile.

Ready

Step 4: SDK Exploitation - Phishing Redirect

Using @whop/iframe SDK's openExternalUrl to redirect victim to attacker-controlled login page.

Ready

Step 5: Direct CSRF (Same-Site Cookie Inclusion)

All .whop.com cookies (including httpOnly) are automatically included in requests to whop.com from this iframe (same eTLD+1).

Ready

Event Log