OpenSSF/OSV advisory MAL-2026-13469 confirms this npm version as malicious. The package's main file (i.js) is an obfuscated browser-side script — its de-obfuscated form is shipped alongside as original.js — that gates execution on window.location.href containing 'noviembrenacional.com'. When loaded in a page on that host, it exfiltrates page HTML and authenticated session state (via fetch with credentials:'include') to a hardcoded...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in xxdxax (npm)
Details
The package's main file (i.js) is an obfuscated browser-side script — its de-obfuscated form is shipped alongside as original.js — that gates execution on window.location.href containing 'noviembrenacional.com'. When loaded in a page on that host, it exfiltrates page HTML and authenticated session state (via fetch with credentials:'include') to a hardcoded https://canarytokens.com/articles/tags/images/j11lq4swuzvslc96qfi9pmsji/submit.aspx endpoint, then abuses the victim's WordPress session on /my-account/editar-cuenta/ to either delete other users' accounts or overwrite the target account's email to nyxalor_25@proton.me and trigger a password reset, resulting in account takeover. Property names, selectors, URLs, WordPress form field names (e.g., _wpnonce, account_first_name), the attacker email, and the target hostname are hidden via \uXXXX unicode escapes and reversed-string tricks ("ecnonpw_".split('').reverse().join('')) to conceal the payload from casual review. The package is not a general-purpose library; it is a targeted CSRF / account-hijack exploit packaged as an npm module. Installing the package does not execute the payload against the Node installer directly (the code uses browser-only APIs and is gated to a specific site), but the package's shipped purpose is offensive action against third-party users of a specific WordPress site.
Decision reason
OpenSSF Malicious Packages via OSV confirms xxdxax@1.0.0 as malicious (MAL-2026-13469): Malicious code in xxdxax (npm)