@cdnshell/loader@0.0.1
Malicious code in @cdnshell/loader (npm)
Analysis
@cdnshell/loader@0.0.1 is a browser-side remote-code-execution loader disguised as a static-assets CDN package. Its single obfuscated script fetches remote JavaScript modules from a configurable base path (configured to "/b/", manifest at "/cx39w3y") and executes the fetched code via the Function constructor. It performs extensive anti-bot fingerprinting (navigator.webdriver, maxTouchPoints, indexedDB, openDatabase, localStorage, WebGL, WebAssembly, RTCPeerConnection) and selects an execution engine based on the parsed browser version. It reloads the parent page every 60 seconds. Remote module names fetched and executed: b1o806cd, bx39w3y, b17gcou3, b1yl2z2i, bqop7bt, b1htfhk8, bgbmelo, b1beuss3, b9x1ptj, b111s01y, b1s6iaad, bka4ijo.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 07:12 PM
- analyzed
- Aug 13, 2026, 07:13 PM
Related advisories
- notafollower@1.0.0
- cilm-ui-commons@1.1.0
- async-lock-queue@3.0.1
- functions-framework-nodejs@1.0.0
- core-js-buffer@1.0.0
- shared-slot-gate@1.1.2
- try-lock-runner@3.2.1
- priority-mutex-lane@2.5.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.