LWA-2026-11956 confirmed malware

@staticj/cropperjs@1.6.0

Malicious code in @staticj/cropperjs (npm)

T1059.007 · JavaScriptT1071.001 · Web ProtocolsT1102 · Web ServiceT1105 · Ingress Tool Transfer

Analysis

@staticj/cropperjs is a combosquat clone of the legitimate cropperjs image-cropping library that ships a remote-code-execution beacon. On module load, cropper.min.js runs an injected IIFE inside the cropMove handler that uses Greasemonkey/Tampermonkey APIs (GM_getValue/GM_setValue/GM_xmlhttpRequest) to rate-limit itself to 15 requests/day, then sends a GET to hxxps://u[.]myquickcash[.]shop/api/spt/upgrade?author=[.][.][.]&name=[.][.][.]&version=[.][.][.]&namespace=[.][.][.]&updateURL=[.][.][.]&timestamp=[.][.]. and executes the response with eval(), giving the remote server arbitrary code execution in the page. The C2 host is u[.]myquickcash[.]shop.

analyzed by
Leitwacht
first seen
Sep 9, 2026, 09:33 AM
analyzed
Sep 9, 2026, 09:34 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.