ddaxx@1.0.0
Malicious code in ddaxx (npm)
Analysis
Package ddaxx@1.0.0 ships an obfuscated browser-side script (package/a.js) that targets the WordPress site noviembreacional[.]com. When loaded on that site, the script: (1) beacons the page HTML to a canarytoken at canarytokens[.]com/tags/feedback/kiwhjd8z03ya08mh9wc04hn/submit.asp?x; (2) reads the logged-in BuddyPress username; (3) if the user is not the site admin, it fetches the user's account deletion page, extracts the CSRF nonce, and POSTs to delete that user's account; (4) if the user IS the site admin, it fetches the account settings page, extracts the nonce, and POSTs to change the account email to nyalorx@25_proton.me, then triggers a WordPress password reset for that email. The script uses fetch() with credentials: 'include' to perform authenticated cross-site requests against the WordPress REST endpoints.
- analyzed by
- Leitwacht
- first seen
- Jul 15, 2026, 08:16 PM
- analyzed
- Jul 15, 2026, 08:17 PM
Related advisories
- xxdxax@1.0.1
- xxdxa@1.0.5
- ts-einkle@1.0.9
- ref-slot@1.0.9
- buffer-wrap-67d7@1.0.0
- prettlog@1.0.10
- ts-ecro@0.0.6
- app-kst-engine@2.1.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.