{"id":"MAL-2026-16277","summary":"Malicious code in xa424234657567 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (0174148efc99cd1130b3b9f2c57599aac0f80ead454fd7dc0f397386db891b0c)\nThe package ships console.js, which when loaded in a browser on any host matching duel.com fetches https://unpkg.com/x6842179305@1.0.3/1.js and https://unpkg.com/x6842179305@1.0.3/ui.js and executes both via (0, eval)(...). On other hosts it redirects the page to duel.com. The declared main/unpkg entry 1.js is a ~740KB single-line Function(\"ZU7mhwD\", \"...\") loader built from hex-escaped char arrays and a rotor-style decoder, with no readable source. Package metadata is placeholder-quality (name xa424234657567, no README, no repository), inconsistent with a library and consistent with a payload-delivery artifact. Consuming this package on a page served under duel.com results in remote, mutable, attacker-controlled code executing in the page context.\n","modified":"2026-09-18T03:30:06.065950329Z","published":"2026-09-18T02:56:09Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020175","import_time":"2026-09-18T03:21:13.036394428Z","modified_time":"2026-09-18T02:56:09Z","sha256":"0174148efc99cd1130b3b9f2c57599aac0f80ead454fd7dc0f397386db891b0c","source":"amazon-inspector","versions":["1.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/xa424234657567/v/1.0.0"}],"affected":[{"package":{"name":"xa424234657567","ecosystem":"npm","purl":"pkg:npm/xa424234657567"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"path":"console.js","sha256":"66d05811bcf8563435c2a13e9dd485c13bb69a6361be4ec553ecac8aed6842f7","tlsh":"efe061f701b954414367555dc20ffd3ba017050a19c8ee66f5f423805f4706f81e28d8"},{"path":"1.js","sha256":"32526067b6d87a46985c3c2003846ec87ec6ef59a71fffe7616f320639500964","tlsh":"4ff4f9ae13e974aac3bf6dc14c37bc9c907909522f5638dafe03d047ed4c1d125a4a6a"}],"package_integrity":[{"hashes":{"sha1":"c9e4e69cc5d938e2b7ebbd9c398578daceced2bc","sha512_sri":"sha512-COOvtg8L+7+aLAJQO1iE1ZtAFFPJSC/LbiS6z9u/uggkWUMuZdFkK2YCL416u8ChDI6LVVfwyXZMbwnPORnMOg=="},"filename":"xa424234657567-1.0.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/xa424234657567/MAL-2026-16277.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}