xxdxax@1.0.1
Malicious code in xxdxax (npm)
Analysis
Package xxdxax@1.0.1 contains a browser-side WordPress account takeover script targeting noviembrenacional[.]com. On execution in a browser context on that domain, the script beacons progress to canarytokens[.]com/articles/tags/images/j11lq4swuzvslc96qfi9pmsji/submit.aspx. For the admin user "noviembrenacional" it changes the account email to [account] and triggers a password reset via /wp-login.php?action=lostpassword. For any other logged-in user it deletes their account via /members/{username}/settings/delete-account/. The package has no lifecycle hooks and no Node.js runtime impact — it is a client-side exploit hosted on the npm registry.
- analyzed by
- Leitwacht
- first seen
- Jul 15, 2026, 07:16 PM
- analyzed
- Jul 15, 2026, 07:17 PM
Related advisories
- xxdxa@1.0.5
- ddaxx@1.0.0
- react-hook-scripts@5.4.2
- @web3-helpers/core@1.0.5
- eth-wallet-helpers@1.0.0
- crypto-validate-lib@1.0.0
- layer2-sdk@1.0.1
- arb-kit@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.