目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

xxdxa

MAL-2026-10752
2026-08-06 23:29:23
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in xxdxa (npm)

文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
0
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npmxxdxa1.0.1
npmxxdxa1.0.2
npmxxdxa1.0.3
npmxxdxa1.0.4
npmxxdxa1.0.5
npmxxdxa1.0.6
npmxxdxa1.0.7
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"schema_version":"1.7.4","id":"MAL-2026-10752","published":"2026-07-16T18:36:36Z","modified":"2026-08-06T23:29:22.725843238Z","summary":"Malicious code in xxdxa (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (26a77171f4b68ff814a7a99b5e51e3d59b9d4ca41fefbd650d2a0f8412878360)\nThe package's sole file i.js (declared as main) is a heavily obfuscated IIFE whose top-level exploit() runs unconditionally when the module is loaded. In a browser context on noviembrenacional.com it reads document.documentElement.outerHTML, base64-encodes it, and POSTs it (body 'type=page_html&data=...') to a hardcoded canarytokens.com endpoint (canarytokens.com/images/terms/e63c36xvesfv8udb0yiy1xztu/contact.php), along with status beacons (start, username, no_user_span, no_nonce, exploit_success, error). When the visitor is a logged-in WordPress user on that site whose username is neither 'JuanCuesta' nor 'noviembrenacional', it fetches /my-account/editar-cuenta/, extracts the save-account-details nonce and referer, and submits a same-origin CSRF POST that overwrites the victim's account email to nyxalor_25@proton.me, then triggers a password reset — an account takeover. For the 'noviembrenacional' admin user it instead POSTs to /members/<user>/settings/delete-account/. In Node (no window), the top-level call throws and the catch handler issues fetch(CANARY_URL + '?type=error&msg=...'), leaking a beacon (including the installer's public IP and an error string) to the attacker's canarytokens URL at require/import time. URLs, DOM property names, form field names, endpoints, and the attacker email are hidden via \\uXXXX escapes, reversed-string decoding (e.g. '/srebmem/'.split('').reverse().join('') → '/members/'), and dead-code XOR expressions, existing solely to conceal the exfiltration destination and WordPress attack targets.\n","affected":[{"package":{"name":"xxdxa","ecosystem":"npm"},"versions":["1.0.3","1.0.2","1.0.4","1.0.5","1.0.7","1.0.1","1.0.6"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"i.js","sha256":"6550221df675fe7a77bcfb4d34ca4bcbc8b13d73a76385b8d3b082765e3bbe46","tlsh":"4c32d2a243779efec8755a049c35be1aecf888b50fd7d02a65073884cd7ebe04791269"}],"package_integrity":[{"filename":"xxdxa-1.0.3.tgz","hashes":{"sha1":"ea9ba28fbc8f45f190bea59cdc61d69c5294e8f4","sha512_sri":"sha512-mRPeE88aCaPu+/KZRm18Qd/oWk4QHtg0yiBAD4xeemvrFt2HRyxMtxs/zIeKollbn8fs8paQ0HsHTgYIHBIcrA=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/xxdxa/v/1.0.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/xxdxa/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/xxdxa/v/1.0.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/xxdxa/v/1.0.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/xxdxa/v/1.0.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/xxdxa/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/xxdxa/v/1.0.6"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-010754","import_time":"2026-07-16T18:54:02.912549687Z","modified_time":"2026-07-16T18:42:34Z","sha256":"0419014b846dad93131788936a2a40257cb27b7c19ab4f74b43d84445b608afa","source":"amazon-inspector","versions":["1.0.3"]},{"id":"IN-MAL-2026-010755","import_time":"2026-07-16T18:54:02.957475438Z","modified_time":"2026-07-16T18:42:42Z","sha256":"0aa8c7ef8c36ef3d4eb1f3c423ca518894ee4abd9c621232cf8d451a9e5d81f9","source":"amazon-inspector","versions":["1.0.2"]},{"id":"IN-MAL-2026-010717","import_time":"2026-07-16T18:54:00.864358936Z","modified_time":"2026-07-16T18:37:02Z","sha256":"26a77171f4b68ff814a7a99b5e51e3d59b9d4ca41fefbd650d2a0f8412878360","source":"amazon-inspector","versions":["1.0.4"]},{"id":"IN-MAL-2026-010716","import_time":"2026-07-16T18:54:00.832547735Z","modified_time":"2026-07-16T18:36:55Z","sha256":"4f93df3b1a546f25702b9d6d35590f05a6f86171cd9852085c2708b5f765242f","source":"amazon-inspector","versions":["1.0.5"]},{"id":"IN-MAL-2026-010714","import_time":"2026-07-16T18:54:00.732302137Z","modified_time":"2026-07-16T18:36:36Z","sha256":"d9f7b472ce0efe03e1eb07b8756f06682c3289fb2b33f544edcd12f71d7e3e56","source":"amazon-inspector","versions":["1.0.7"]},{"id":"IN-MAL-2026-010760","import_time":"2026-07-16T18:54:03.149350522Z","modified_time":"2026-07-16T18:43:23Z","sha256":"f8c8cc7d71b667ac9ab8421c504e75d408ec3354aa77d47d1287cb8c190a85e1","source":"amazon-inspector","versions":["1.0.1"]},{"id":"IN-MAL-2026-016768","import_time":"2026-08-06T23:25:08.328922359Z","modified_time":"2026-08-06T19:23:40Z","sha256":"11c6960c4542c305f28645eaead69587981de8358ce99e5205dd312807c0a247","source":"amazon-inspector","versions":["1.0.6"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}

数据来源:OpenSSF Malicious Packages · Apache-2.0