xxdxa@1.0.5
Malicious code in xxdxa (npm)
Analysis
Package xxdxa@1.0.5 ships an obfuscated browser-side JavaScript payload (package/i.js) that targets the WordPress site noviembreaccional[.]com. When loaded in a browser on that domain, the script exfiltrates the full page HTML and the logged-in username to a canarytokens[.]com beacon (hxxps://canarytokens[.]com/images/terms/e63c36xvesfv8udb0yii1xztu/contact[.]php). If the logged-in user is not the site owner ("JuanCuates"), the script fetches the victim's account settings page, extracts the WordPress nonce, and POSTs to delete the victim's account. If the logged-in user IS the site owner, the script fetches the account edit page, extracts the nonce and profile fields, then POSTs to change the account email to [account] and triggers a password reset via wp-login.php?action=lostpassword — achieving full account takeover. Every step of the attack beacons status to the canarytoken URL.
- analyzed by
- Leitwacht
- first seen
- Jul 15, 2026, 04:56 PM
- analyzed
- Jul 15, 2026, 04:57 PM
Related advisories
- ddaxx@1.0.0
- xxdxax@1.0.1
- eth-wallet-helpers@1.0.0
- base58-utils@1.0.3
- eth-dev@1.0.2
- express-mongo-limit@2.0.1
- pinokio-redis@1.0.127
- zredis-typed@1.0.127
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.