xa424234657567@1.0.0
Vulnerability report · Last retrieved from osv.dev September 18, 2026 at 6:39 AM UTC
OSV ID
MAL-2026-16277
Ecosystem
npm
Summary
The package ships console.js, which when loaded in a browser on any host matching duel.com fetches https://unpkg.com/x6842179305@1.0.3/1.js and https://unpkg.com/x6842179305@1.0.3/ui.js and executes both via (0, eval)(...). On other hosts it redirects the page to duel.com. The declared main/unpkg entry 1.js is a ~740KB single-line Function("ZU7mhwD", "...") loader built from hex-escaped char arrays and a rotor-style decoder, with no readable source. Package metadata is placeholder-quality (name xa424234657567, no README, no repository), inconsistent with a library and consistent with a payload-delivery artifact. Consuming this package on a page served under duel.com results in remote, mutable, attacker-controlled code executing in the page context.
Source: amazon-inspector (0174148efc99cd1130b3b9f2c57599aac0f80ead454fd7dc0f397386db891b0c)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.