LWA-2026-11955 MAL-2026-16081 ↗ confirmed malware

@staticj/cropperxmjs@1.6.0

Malicious code in @staticj/cropperxmjs (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1195.002 · Compromise Software Supply Chain

Analysis

@staticj/cropperxmjs@1.6.0 is a trojanized clone of the Cropper.js image-cropping library. Both cropper.min.js and cropper.test.min.js contain an injected block inside the cropMove handler that reads userscript metadata (author, name, version, namespace, updateURL) and sends an HTTP GET to hxxps://u[.]myquickcash[.]shop/api/spt/upgrade?author=[.][.][.]&name=[.][.][.]&version=[.][.][.]&namespace=[.][.][.]&updateURL=[.][.][.]&timestamp=[.][.]. The response body is passed to eval(), executing arbitrary remote code supplied by the server. The beacon is rate-limited to 15 requests per day via GM_getValue/GM_setValue storage. This is a remote-code-execution / second-stage loader.

analyzed by
Leitwacht
first seen
Sep 9, 2026, 09:18 AM
analyzed
Sep 9, 2026, 09:20 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.