LWA-2026-5527 confirmed malware
xeiko-cdn@1.0.0
Malicious code in xeiko-cdn (npm)
T1195.002 · Compromise Software Supply ChainT1562.001 · Disable or Modify ToolsT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1496 · Resource Hijacking
Analysis
Package xeiko-cdn is a fake CDN package that, when loaded in a browser, injects a remote tracking script (node12[.]aizhantj[.]com:21233) and creates a full-page iframe overlay to a date-rotating subdomain on 182[.]run. It also disables right-click context menu, text selection, and the F12 developer tools key to prevent users from inspecting the injected content. The iframe URL follows a daily-rotation pattern using the current date (DDMM[.]182[.]run). This is a supply-chain compromise distributing browser-side ad-injection / clickjack / tracking payloads via npm.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 06:58 AM
- analyzed
- Jun 16, 2026, 06:59 AM
Related advisories
- gpt-terminal-cli@1.0.0
- stellarfixer@1.0.0
- web3-token-helper@1.1.3
- mev-shield@1.4.2
- fb-cards-form-no-resident-information@20.4.4
- crypto-base58@1.0.1
- zhuanhua@1.1.99
- @dilxzphrine/baileys@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.