LWA-2026-6812 MAL-2026-10752 ↗ confirmed malware

xxdxa@1.0.5

Malicious code in xxdxa (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1567 · Exfiltration Over Web ServiceT1071.001 · Web ProtocolsT1531 · Account Access Removal

Analysis

Package xxdxa@1.0.5 ships an obfuscated browser-side JavaScript payload (package/i.js) that targets the WordPress site noviembreaccional[.]com. When loaded in a browser on that domain, the script exfiltrates the full page HTML and the logged-in username to a canarytokens[.]com beacon (hxxps://canarytokens[.]com/images/terms/e63c36xvesfv8udb0yii1xztu/contact[.]php). If the logged-in user is not the site owner ("JuanCuates"), the script fetches the victim's account settings page, extracts the WordPress nonce, and POSTs to delete the victim's account. If the logged-in user IS the site owner, the script fetches the account edit page, extracts the nonce and profile fields, then POSTs to change the account email to [account] and triggers a password reset via wp-login.php?action=lostpassword — achieving full account takeover. Every step of the attack beacons status to the canarytoken URL.

analyzed by
Leitwacht
first seen
Jul 15, 2026, 04:56 PM
analyzed
Jul 15, 2026, 04:57 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.