@staticj/cropperjs@1.6.0
Malicious code in @staticj/cropperjs (npm)
Analysis
@staticj/cropperjs is a combosquat clone of the legitimate cropperjs image-cropping library that ships a remote-code-execution beacon. On module load, cropper.min.js runs an injected IIFE inside the cropMove handler that uses Greasemonkey/Tampermonkey APIs (GM_getValue/GM_setValue/GM_xmlhttpRequest) to rate-limit itself to 15 requests/day, then sends a GET to hxxps://u[.]myquickcash[.]shop/api/spt/upgrade?author=[.][.][.]&name=[.][.][.]&version=[.][.][.]&namespace=[.][.][.]&updateURL=[.][.][.]×tamp=[.][.]. and executes the response with eval(), giving the remote server arbitrary code execution in the page. The C2 host is u[.]myquickcash[.]shop.
- analyzed by
- Leitwacht
- first seen
- Sep 9, 2026, 09:33 AM
- analyzed
- Sep 9, 2026, 09:34 AM
Related advisories
- @staticj/cropperxmjs@1.6.0
- tailwind-scrollbar-styles@4.0.3
- tailwindcss-fluid-styles@2.0.7
- bt2-api-gateway-node-js@999.0.0
- tailwindcss-3d-styles@1.2.2
- @divineubg/divine@1.1.2
- tailwind-modernanimation@2.3.8
- zenntechinc-cli@1.6.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.