MAL-2026-16277
Malicious code in xa424234657567 (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (0174148efc99cd1130b3b9f2c57599aac0f80ead454fd7dc0f397386db891b0c) The package ships console.js, which when loaded in a browser on any host matching duel.com fetches https://unpkg.com/x6842179305@1.0.3/1.js and https://unpkg.com/x6842179305@1.0.3/ui.js and executes both via (0, eval)(...). On other hosts it redirects the page to duel.com. The declared main/unpkg entry 1.js is a ~740KB single-line Function("ZU7mhwD", "...") loader built from hex-escaped char arrays and a rotor-style decoder, with no readable source. Package metadata is placeholder-quality (name xa424234657567, no README, no repository), inconsistent with a library and consistent with a payload-delivery artifact. Consuming this package on a page served under duel.com results in remote, mutable, attacker-controlled code executing in the page context.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for xa424234657567 (npm). Pin to a known-safe version or switch to an alternative.