OpenSSF/OSV advisory MAL-2026-16337 confirms this npm version as malicious. my-cdn-script@1.0.0 ships a client-side payment-card skimmer in script.js. When loaded on a checkout page, the script injects a fake card-input form into the Alpha Bank hosted payment method and captures the card number, expiry, CVC together with the shopper's name, address, city, region, postcode, phone, and page origin...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in my-cdn-script (npm)
Details
my-cdn-script@1.0.0 ships a client-side payment-card skimmer in script.js. When loaded on a checkout page, the script injects a fake card-input form into the Alpha Bank hosted payment method and captures the card number, expiry, CVC together with the shopper's name, address, city, region, postcode, phone, and page origin. The concatenated payload is encoded byte-by-byte, wrapped in a Blob with type 'image/png' to disguise it as an image upload, and POSTed to the hardcoded attacker endpoint https://ungpkg.top/gate. The script uses uniform bracket-notation property access to defeat static string scans, sets a sessionStorage flag to avoid re-sending, and gates itself off when admin-panel cookies/localStorage keys (psAdminLang, psAdminTab, psAdminTheme, _ga_8F4XM9P3R51) are present so a merchant testing their own checkout does not observe the theft. Any site that includes this package on its checkout page will have its customers' payment card data and PII silently harvested and sent to ungpkg.top.
Decision reason
No blocking static signals were detected.