LWA-2026-6823 MAL-2026-13469 ↗ confirmed malware

xxdxax@1.0.1

Malicious code in xxdxax (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1531 · Account Access RemovalT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Package xxdxax@1.0.1 contains a browser-side WordPress account takeover script targeting noviembrenacional[.]com. On execution in a browser context on that domain, the script beacons progress to canarytokens[.]com/articles/tags/images/j11lq4swuzvslc96qfi9pmsji/submit.aspx. For the admin user "noviembrenacional" it changes the account email to [account] and triggers a password reset via /wp-login.php?action=lostpassword. For any other logged-in user it deletes their account via /members/{username}/settings/delete-account/. The package has no lifecycle hooks and no Node.js runtime impact — it is a client-side exploit hosted on the npm registry.

analyzed by
Leitwacht
first seen
Jul 15, 2026, 07:16 PM
analyzed
Jul 15, 2026, 07:17 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.