@staticj/cropperxmjs@1.6.0
Malicious code in @staticj/cropperxmjs (npm)
Analysis
@staticj/cropperxmjs@1.6.0 is a trojanized clone of the Cropper.js image-cropping library. Both cropper.min.js and cropper.test.min.js contain an injected block inside the cropMove handler that reads userscript metadata (author, name, version, namespace, updateURL) and sends an HTTP GET to hxxps://u[.]myquickcash[.]shop/api/spt/upgrade?author=[.][.][.]&name=[.][.][.]&version=[.][.][.]&namespace=[.][.][.]&updateURL=[.][.][.]×tamp=[.][.]. The response body is passed to eval(), executing arbitrary remote code supplied by the server. The beacon is rate-limited to 15 requests per day via GM_getValue/GM_setValue storage. This is a remote-code-execution / second-stage loader.
- analyzed by
- Leitwacht
- first seen
- Sep 9, 2026, 09:18 AM
- analyzed
- Sep 9, 2026, 09:20 AM
Related advisories
- @staticj/cropperjs@1.6.0
- punypump@1.2.4
- open-item-validator@1.0.2
- feishu-docx-mcp@0.3.2
- rojo-rbx@1.4.3
- node-helper@1.5.4
- multicore-kit@1.1.5
- jwt-logger@2.1.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.