MAL-2026-13431
Dashboard / Malicious Package / MAL-2026-13431
MAL-2026-13431
Summary: Malicious code in @itsreduxtm/unpkg-xss-test (npm)
Details: Source: amazon-inspector (39614132e3675ec887b41aa6834ac54cce90e248d43f008345444b86e1870d82) payload.js is declared as the package `main` and runs an IIFE immediately on require/import. It fetches a wordlist of Linux binary names from https://unpkg.com/@itsreduxtm/[email protected]/binlist.txt and issues concurrent HEAD requests to https://entretienextremejb.ca/bin/<name> for each entry, sourcing the traffic from the installer's machine and IP address. The package name (`unpkg-xss-test`) and GTFOBins-style wordlist shape indicate this is a browser XSS-delivered path-enumeration payload; when loaded in Node (fetch is global in Node 18+), the installer conducts the scan against a third party. This covertly weaponizes the installer's identity for reconnaissance against an unrelated site, exposing the installer to abuse reports, IP blocklisting, and potential legal complaints for unauthorized scanning.
References: https://www.npmjs.com/package/@itsreduxtm/unpkg-xss-test/v/1.0.5, https://www.npmjs.com/package/@itsreduxtm/unpkg-xss-test/v/1.0.9
Affected packages
Package
Name: @itsreduxtm/unpkg-xss-test
Purl: pkg:npm/%40itsreduxtm/unpkg-xss-test
Affected ranges
Type: N/A
Events:
