This page runs inside a Whop app iframe at *.apps.whop.com
Cookies readable from iframe via document.cookie (shared .whop.com scope):
Extracting...
Stolen cookies sent to ATTACKER_SERVER/collect:
Waiting...
Attacker server uses stolen cookies + httpOnly cookies (sent automatically with same-site requests) to modify victim's profile.
Ready
Using @whop/iframe SDK's openExternalUrl to redirect victim to attacker-controlled login page.
Ready
All .whop.com cookies (including httpOnly) are automatically included in requests to whop.com from this iframe (same eTLD+1).
Ready