OSV ID
MAL-2026-13469
Ecosystem
npm
Summary
The package's main file (i.js) is an obfuscated browser-side script — its de-obfuscated form is shipped alongside as original.js — that gates execution on window.location.href containing 'noviembrenacional.com'. When loaded in a page on that host, it exfiltrates page HTML and authenticated session state (via fetch with credentials:'include') to a hardcoded https://canarytokens.com/articles/tags/images/j11lq4swuzvslc96qfi9pmsji/submit.aspx endpoint, then abuses the victim's WordPress session on /my-account/editar-cuenta/ to either delete other users' accounts or overwrite the target account's email to nyxalor_25@proton.me and trigger a password reset, resulting in account takeover. Property names, selectors, URLs, WordPress form field names (e.g., _wpnonce, account_first_name), the attacker email, and the target hostname are hidden via \uXXXX unicode escapes and reversed-string tricks ("ecnonpw_".split('').reverse().join('')) to conceal the payload from casual review. The package is not a general-purpose library; it is a targeted CSRF / account-hijack exploit packaged as an npm module. Installing the package does not execute the payload against the Node installer directly (the code uses browser-only APIs and is gated to a specific site), but the package's shipped purpose is offensive action against third-party users of a specific WordPress site.
Source: amazon-inspector (8922341a391ea133f4e6b95d55da2a7ee404c99a9f88f75bdc2698d3f03cc97c)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.