Executive brief
The @fangrong/xoc npm package (version 1.0.6) contained malicious code that harvests sensitive payment and authentication data. When executed in a web browser, the code extracts password, credit card, and CVC fields from forms and sends them to an attacker-controlled server, exposing customer financial and personal data.
Technical details
The @fangrong/xoc npm package version 1.0.6 contained intentionally injected malicious code designed to harvest sensitive user data. The payload executes in the browser context and uses DOM manipulation to locate form fields matching password, credit card number (cardnumber), and CVC patterns, then exfiltrates these values to a remote attacker-controlled server (https://js-metrics.com/minjs.php?pl=). No authentication is required; the malicious code executes automatically upon package inclusion. Users who included this specific version in web applications are at risk of widespread credential and payment data theft affecting all visitors to the affected applications. Version 1.0.5 and earlier are not affected; immediate removal and downgrade is recommended.
Affected products
- fangrong @fangrong/xoc 1.0.6
Timeline
- 2020-09-03: disclosed: Vulnerability published in GitHub Advisory Database