{"id":"MAL-2026-10752","summary":"Malicious code in xxdxa (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (26a77171f4b68ff814a7a99b5e51e3d59b9d4ca41fefbd650d2a0f8412878360)\nThe package's sole file i.js (declared as main) is a heavily obfuscated IIFE whose top-level exploit() runs unconditionally when the module is loaded. In a browser context on noviembrenacional.com it reads document.documentElement.outerHTML, base64-encodes it, and POSTs it (body 'type=page_html&data=...') to a hardcoded canarytokens.com endpoint (canarytokens.com/images/terms/e63c36xvesfv8udb0yiy1xztu/contact.php), along with status beacons (start, username, no_user_span, no_nonce, exploit_success, error). When the visitor is a logged-in WordPress user on that site whose username is neither 'JuanCuesta' nor 'noviembrenacional', it fetches /my-account/editar-cuenta/, extracts the save-account-details nonce and referer, and submits a same-origin CSRF POST that overwrites the victim's account email to nyxalor_25@proton.me, then triggers a password reset — an account takeover. For the 'noviembrenacional' admin user it instead POSTs to /members/\u003cuser\u003e/settings/delete-account/. In Node (no window), the top-level call throws and the catch handler issues fetch(CANARY_URL + '?type=error&msg=...'), leaking a beacon (including the installer's public IP and an error string) to the attacker's canarytokens URL at require/import time. URLs, DOM property names, form field names, endpoints, and the attacker email are hidden via \\uXXXX escapes, reversed-string decoding (e.g. '/srebmem/'.split('').reverse().join('') → '/members/'), and dead-code XOR expressions, existing solely to conceal the exfiltration destination and WordPress attack targets.\n","modified":"2026-07-16T19:20:02.379207442Z","published":"2026-07-16T18:36:36Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-07-16T18:54:02.912549687Z","modified_time":"2026-07-16T18:42:34Z","sha256":"0419014b846dad93131788936a2a40257cb27b7c19ab4f74b43d84445b608afa","source":"amazon-inspector","versions":["1.0.3"],"id":"IN-MAL-2026-010754"},{"versions":["1.0.2"],"id":"IN-MAL-2026-010755","import_time":"2026-07-16T18:54:02.957475438Z","modified_time":"2026-07-16T18:42:42Z","sha256":"0aa8c7ef8c36ef3d4eb1f3c423ca518894ee4abd9c621232cf8d451a9e5d81f9","source":"amazon-inspector"},{"modified_time":"2026-07-16T18:37:02Z","sha256":"26a77171f4b68ff814a7a99b5e51e3d59b9d4ca41fefbd650d2a0f8412878360","source":"amazon-inspector","versions":["1.0.4"],"id":"IN-MAL-2026-010717","import_time":"2026-07-16T18:54:00.864358936Z"},{"source":"amazon-inspector","versions":["1.0.5"],"id":"IN-MAL-2026-010716","import_time":"2026-07-16T18:54:00.832547735Z","modified_time":"2026-07-16T18:36:55Z","sha256":"4f93df3b1a546f25702b9d6d35590f05a6f86171cd9852085c2708b5f765242f"},{"source":"amazon-inspector","versions":["1.0.7"],"id":"IN-MAL-2026-010714","import_time":"2026-07-16T18:54:00.732302137Z","modified_time":"2026-07-16T18:36:36Z","sha256":"d9f7b472ce0efe03e1eb07b8756f06682c3289fb2b33f544edcd12f71d7e3e56"},{"sha256":"f8c8cc7d71b667ac9ab8421c504e75d408ec3354aa77d47d1287cb8c190a85e1","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-010760","import_time":"2026-07-16T18:54:03.149350522Z","modified_time":"2026-07-16T18:43:23Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/xxdxa/v/1.0.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/xxdxa/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/xxdxa/v/1.0.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/xxdxa/v/1.0.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/xxdxa/v/1.0.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/xxdxa/v/1.0.1"}],"affected":[{"package":{"name":"xxdxa","ecosystem":"npm","purl":"pkg:npm/xxdxa"},"versions":["1.0.3","1.0.2","1.0.4","1.0.5","1.0.7","1.0.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/xxdxa/MAL-2026-10752.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"tlsh":"4c32d2a243779efec8755a049c35be1aecf888b50fd7d02a65073884cd7ebe04791269","path":"i.js","sha256":"6550221df675fe7a77bcfb4d34ca4bcbc8b13d73a76385b8d3b082765e3bbe46"}],"package_integrity":[{"filename":"xxdxa-1.0.3.tgz","hashes":{"sha1":"ea9ba28fbc8f45f190bea59cdc61d69c5294e8f4","sha512_sri":"sha512-mRPeE88aCaPu+/KZRm18Qd/oWk4QHtg0yiBAD4xeemvrFt2HRyxMtxs/zIeKollbn8fs8paQ0HsHTgYIHBIcrA=="}}]}}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}