Malicious code in yakuza0 (npm)
The package ships code that binds outbound network calls to a hardcoded non-standard host, https://registry-pxnpm.rdc.nfjbill.ren, from cli/index.js (fetch calls at lines 513, 554, 623 alongside a reference to process.versions for host fingerprinting). Additional files server/proxy/tire.js and server/proxy/csrf.js combine child_process usage with curl-based POST/GET operations, mixing shell command execution with outbound HTTP to non-registry endpoints. The destination host is not the npm registry or a documented publisher domain; its name mimics the format of a private npm registry, and it is invoked from top-level module code paths rather than a user-invoked API. The composition — hardcoded attacker-shaped endpoint, runtime process/version fingerprinting, curl-driven POSTs, and child_process shell execution wired to the same network paths — matches the shape of installer-targeted exfiltration and remote command execution.
MAL-2026-13605 is recorded against 1 package.
Published on 7 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| yakuza0 | — | — |
References
Free Vulnerability Check
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-13605 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.