MAL-2026-10104
Dashboard / Malicious Package / MAL-2026-10104
MAL-2026-10104
Summary: Malicious code in px8my (npm)
Details: Source: amazon-inspector (7da37dfbaa4b355a75e38c244bc5614299ecc5a1f3bc1dd072fdc7c4f2dc13b9) px8my's `main` entry is a browser-side script that injects a full-screen iframe pointing at a hardcoded remote URL (`https://mfmz.gzhrjq.cn/H.html?c=0gjr`). The tarball also ships `update_px8my.sh`, a maintainer helper that rewrites the redirect domain in `px.js`, bumps the patch version, runs `npm publish`, then calls the jsDelivr purge API — documenting an operational model in which the npm registry + jsDelivr CDN are used as a mutable redirect distribution channel with the destination domain rotated on demand. Installing this as an npm dependency does not directly harm the installer: there are no lifecycle scripts, and `require()`ing the module in Node would throw because it references `document`. The impact surface is downstream websites/end-users that load `px8my/px.js` via the jsDelivr CDN, which are redirected to the maintainer-controlled destination. The package has no library value; it exists to abuse npm namespace + jsDelivr as a redirector. Because the installer is not directly attacked but the package is clearly designed as an abuse vehicle, route to human review for a takedown decision. Source: ghsa-malware (78ae5dc7b5995ac8381a5716c7733e93d7de2c6500063fba58c05085cd03999d) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
References: https://www.npmjs.com/package/px8my/v/1.0.32, https://www.npmjs.com/package/px8my/v/1.0.23, https://www.npmjs.com/package/px8my/v/1.0.13, https://www.npmjs.com/package/px8my/v/1.0.35, https://www.npmjs.com/package/px8my/v/1.0.22, https://www.npmjs.com/package/px8my/v/1.0.36, https://github.com/advisories/GHSA-9869-r2r5-fff6, https://www.npmjs.com/package/px8my/v/1.0.48, https://www.npmjs.com/package/px8my/v/1.0.47, https://www.npmjs.com/package/px8my/v/1.0.45, https://www.npmjs.com/package/px8my/v/1.0.44, https://www.npmjs.com/package/px8my/v/1.0.31, https://www.npmjs.com/package/px8my/v/1.0.25, https://www.npmjs.com/package/px8my/v/1.0.30, https://www.npmjs.com/package/px8my/v/1.0.38, https://www.npmjs.com/package/px8my/v/1.0.43, https://www.npmjs.com/package/px8my/v/1.0.37, https://www.npmjs.com/package/px8my/v/1.0.26, https://www.npmjs.com/package/px8my/v/1.0.39, https://www.npmjs.com/package/px8my/v/1.0.27, https://www.npmjs.com/package/px8my/v/1.0.34, https://www.npmjs.com/package/px8my/v/1.0.50, https://www.npmjs.com/package/px8my/v/1.0.33, https://www.npmjs.com/package/px8my/v/1.0.40, https://www.npmjs.com/package/px8my/v/1.0.46, https://www.npmjs.com/package/px8my/v/1.0.52, https://www.npmjs.com/package/px8my/v/1.0.29, https://www.npmjs.com/package/px8my/v/1.0.53, https://www.npmjs.com/package/px8my/v/1.0.54, https://www.npmjs.com/package/px8my/v/1.0.28, https://www.npmjs.com/package/px8my/v/1.0.49, https://www.npmjs.com/package/px8my/v/1.0.24, https://www.npmjs.com/package/px8my/v/1.0.42, https://www.npmjs.com/package/px8my/v/1.0.51, https://www.npmjs.com/package/px8my/v/1.0.41
Affected packages
Package
Name: px8my
Purl: pkg:npm/px8my
Affected ranges
Type: N/A
Events:
