MAL-2026-10104

    Dashboard / Malicious Package / MAL-2026-10104

    MAL-2026-10104

    Published: 9 Jul 2026Last Modified: 5 Aug 2026Aliases: 
    GHSA-9869-r2r5-fff6

    Summary: Malicious code in px8my (npm)

    Details: Source: amazon-inspector (7da37dfbaa4b355a75e38c244bc5614299ecc5a1f3bc1dd072fdc7c4f2dc13b9) px8my's `main` entry is a browser-side script that injects a full-screen iframe pointing at a hardcoded remote URL (`https://mfmz.gzhrjq.cn/H.html?c=0gjr`). The tarball also ships `update_px8my.sh`, a maintainer helper that rewrites the redirect domain in `px.js`, bumps the patch version, runs `npm publish`, then calls the jsDelivr purge API — documenting an operational model in which the npm registry + jsDelivr CDN are used as a mutable redirect distribution channel with the destination domain rotated on demand. Installing this as an npm dependency does not directly harm the installer: there are no lifecycle scripts, and `require()`ing the module in Node would throw because it references `document`. The impact surface is downstream websites/end-users that load `px8my/px.js` via the jsDelivr CDN, which are redirected to the maintainer-controlled destination. The package has no library value; it exists to abuse npm namespace + jsDelivr as a redirector. Because the installer is not directly attacked but the package is clearly designed as an abuse vehicle, route to human review for a takedown decision. Source: ghsa-malware (78ae5dc7b5995ac8381a5716c7733e93d7de2c6500063fba58c05085cd03999d) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

    References: https://www.npmjs.com/package/px8my/v/1.0.32, https://www.npmjs.com/package/px8my/v/1.0.23, https://www.npmjs.com/package/px8my/v/1.0.13, https://www.npmjs.com/package/px8my/v/1.0.35, https://www.npmjs.com/package/px8my/v/1.0.22, https://www.npmjs.com/package/px8my/v/1.0.36, https://github.com/advisories/GHSA-9869-r2r5-fff6, https://www.npmjs.com/package/px8my/v/1.0.48, https://www.npmjs.com/package/px8my/v/1.0.47, https://www.npmjs.com/package/px8my/v/1.0.45, https://www.npmjs.com/package/px8my/v/1.0.44, https://www.npmjs.com/package/px8my/v/1.0.31, https://www.npmjs.com/package/px8my/v/1.0.25, https://www.npmjs.com/package/px8my/v/1.0.30, https://www.npmjs.com/package/px8my/v/1.0.38, https://www.npmjs.com/package/px8my/v/1.0.43, https://www.npmjs.com/package/px8my/v/1.0.37, https://www.npmjs.com/package/px8my/v/1.0.26, https://www.npmjs.com/package/px8my/v/1.0.39, https://www.npmjs.com/package/px8my/v/1.0.27, https://www.npmjs.com/package/px8my/v/1.0.34, https://www.npmjs.com/package/px8my/v/1.0.50, https://www.npmjs.com/package/px8my/v/1.0.33, https://www.npmjs.com/package/px8my/v/1.0.40, https://www.npmjs.com/package/px8my/v/1.0.46, https://www.npmjs.com/package/px8my/v/1.0.52, https://www.npmjs.com/package/px8my/v/1.0.29, https://www.npmjs.com/package/px8my/v/1.0.53, https://www.npmjs.com/package/px8my/v/1.0.54, https://www.npmjs.com/package/px8my/v/1.0.28, https://www.npmjs.com/package/px8my/v/1.0.49, https://www.npmjs.com/package/px8my/v/1.0.24, https://www.npmjs.com/package/px8my/v/1.0.42, https://www.npmjs.com/package/px8my/v/1.0.51, https://www.npmjs.com/package/px8my/v/1.0.41

    Affected packages

    Package

    Name: px8my

    Purl: pkg:npm/px8my

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.32
    1.0.23
    1.0.13
    1.0.35
    1.0.22
    1.0.36
    1.0.54
    1.0.53
    1.0.52
    1.0.51
    1.0.50
    1.0.49
    1.0.48
    1.0.47
    1.0.46
    1.0.45
    1.0.44
    1.0.43
    1.0.42
    1.0.41
    1.0.40
    1.0.39
    1.0.38
    1.0.37
    1.0.34
    1.0.33
    1.0.31
    1.0.30
    1.0.29
    1.0.28
    1.0.27
    1.0.26
    1.0.25
    1.0.24
    MAL-2026-10104 | CVE-DB