VYPR

npm · Malicious package advisory

Malware

my-cdn-script

GHSA-r55v-7qcq-fvr9

Malicious code in my-cdn-script (npm)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (e634f64d71797bbefdaf62bd0f2092d1cace77af2a07fd41e7d2347a14bb001b)
[email protected] ships a client-side payment-card skimmer in script.js. When loaded on a checkout page, the script injects a fake card-input form into the Alpha Bank hosted payment method and captures the card number, expiry, CVC together with the shopper's name, address, city, region, postcode, phone, and page origin. The concatenated payload is encoded byte-by-byte, wrapped in a Blob with type 'image/png' to disguise it as an image upload, and POSTed to the hardcoded attacker endpoint https://ungpkg.top/gate. The script uses uniform bracket-notation property access to defeat static string scans, sets a sessionStorage flag to avoid re-sending, and gates itself off when admin-panel cookies/localStorage keys (psAdminLang, psAdminTab, psAdminTheme, _ga_8F4XM9P3R51) are present so a merchant testing their own checkout does not observe the theft. Any site that includes this package on its checkout page will have its customers' payment card data and PII silently harvested and sent to ungpkg.top.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/af486be301974b4c4068b1c7baa77731f37fa05e/osv/malicious/npm/my-cdn-script/MAL-2026-16337.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/af486be301974b4c4068b1c7baa77731f37fa05e/osv/malicious/npm/my-cdn-script/MAL-2026-16337.json
- https://www.npmjs.com/package/my-cdn-script/v/1.0.0
- https://github.com/advisories/GHSA-r55v-7qcq-fvr9

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.