The package contains an obfuscated browser exploit but its declared entrypoint is absent. If either payload file is loaded in a browser on the guarded target domain, it exfiltrates page/account data and performs authenticated account takeover or deletion requests.
Static reason
No blocking static signals were detected.
Trigger
Explicit loading or execution of `i.js` or `original.js` in a browser at the target domain.
Impact
Account deletion or takeover through email change and password reset; disclosure of page HTML and CSRF nonces.
Mechanism
Guarded DOM exfiltration plus authenticated account mutation.
Rationale
Concrete malicious account-takeover, deletion, and exfiltration logic exists, but no lifecycle hook or declared reachable entrypoint activates it. Treat it as a staged payload carrier requiring a warning rather than a publish block.
Evidence
package.jsoni.jsoriginal.js
Network endpoints4
canarytokens.com/articles/tags/images/j11lq4swuzvslc96qfi9pmsji/submit.aspx/members/<username>/settings/delete-account//my-account/editar-cuenta//wp-login.php?action=lostpassword