-= Per source details. Do not edit below this line.=-
The package's main file (i.js) is an obfuscated browser-side script — its de-obfuscated form is shipped alongside as original.js — that gates execution on window.location.href containing 'noviembrenacional.com'. When loaded in a page on that host, it exfiltrates page HTML and authenticated session state (via fetch with credentials:'include') to a hardcoded https://canarytokens.com/articles/tags/images/j11lq4swuzvslc96qfi9pmsji/submit.aspx endpoint, then abuses the victim's WordPress session on /my-account/editar-cuenta/ to either delete other users' accounts or overwrite the target account's email to nyxalor_25@proton.me and trigger a password reset, resulting in account takeover. Property names, selectors, URLs, WordPress form field names (e.g., wpnonce, account_first_name), the attacker email, and the target hostname are hidden via \uXXXX unicode escapes and reversed-string tricks ("ecnonpw".split('').reverse().join('')) to conceal the payload from casual review. The package is not a general-purpose library; it is a targeted CSRF / account-hijack exploit packaged as an npm module. Installing the package does not execute the payload against the Node installer directly (the code uses browser-only APIs and is gated to a specific site), but the package's shipped purpose is offensive action against third-party users of a specific WordPress site.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-016767",
"import_time": "2026-08-06T23:25:08.264496712Z",
"modified_time": "2026-08-06T19:23:28Z",
"sha256": "4ed3cc7181de938df5ab662b7eaa29f8a9eabcd42f2584386ece03824077b918",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-016766",
"import_time": "2026-08-06T23:25:08.221358999Z",
"modified_time": "2026-08-06T19:23:10Z",
"sha256": "8922341a391ea133f4e6b95d55da2a7ee404c99a9f88f75bdc2698d3f03cc97c",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "original.js",
"sha256": "f299a4d07e1b7c05084d728ac0f56805cb1061578ee5ba96fa9ab6675b80ded8",
"tlsh": "24b1116520f706614c7371de63fba60aa419611b38a7d5c83fac5b081f8ce559c32bec"
},
{
"path": "i.js",
"sha256": "41cceb032f1d37183debf49a308f348b9ce40af6b8df6d920bc9f1370ccac939",
"tlsh": "6342c4a643779ebec8705a048c35ae1aedf884f61fe7d02a69073884cc7e7f14791259"
}
],
"package_integrity": [
{
"filename": "xxdxax-1.0.0.tgz",
"hashes": {
"sha1": "9e26954db3be77a475752bb8c5da61cbd460fb27",
"sha512_sri": "sha512-oKpIOZaO7gtOa0eQ8ZzSrokr8aLKdoTdT1gjiEKw8h/mmRyYqsHOZ+6tTySPuMvM4FSunydOgLGbkH2jV8A5KQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/xxdxax/MAL-2026-13469.json"