LWA-2026-6826 confirmed malware

ddaxx@1.0.0

Malicious code in ddaxx (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1567 · Exfiltration Over Web ServiceT1531 · Account Access RemovalT1098 · Account Manipulation

Analysis

Package ddaxx@1.0.0 ships an obfuscated browser-side script (package/a.js) that targets the WordPress site noviembreacional[.]com. When loaded on that site, the script: (1) beacons the page HTML to a canarytoken at canarytokens[.]com/tags/feedback/kiwhjd8z03ya08mh9wc04hn/submit.asp?x; (2) reads the logged-in BuddyPress username; (3) if the user is not the site admin, it fetches the user's account deletion page, extracts the CSRF nonce, and POSTs to delete that user's account; (4) if the user IS the site admin, it fetches the account settings page, extracts the nonce, and POSTs to change the account email to nyalorx@25_proton.me, then triggers a WordPress password reset for that email. The script uses fetch() with credentials: 'include' to perform authenticated cross-site requests against the WordPress REST endpoints.

analyzed by
Leitwacht
first seen
Jul 15, 2026, 08:16 PM
analyzed
Jul 15, 2026, 08:17 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.