npm · Malicious package advisory
Malware6-viewsight-web
MAL-2026-14365
Malicious code in 6-viewsight-web (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (96501ebb5a5bb3858767545e256cdcfd23f164f4435c109d206f421771ce6e68) The package's main module is a self-executing IIFE that fetches HTML from https://bitbucket.org/p2p-alt-public/p2p-emis/raw/main/GameWebSight and injects it into the consuming page's DOM, re-creating each <script> element so its contents execute in the page's JavaScript context. The URL points at the mutable `main` branch with no version pin, hash, or signature check, so whoever controls the `p2p-alt-public/p2p-emis` Bitbucket repository can change the payload at any time and have it run in every application that loads this package. package.json ships with empty author metadata, MIT default, and a generic 'Website loader for remote HTML content' description, and there is no relationship between the publishing npm identity and the Bitbucket account hosting the fetched code.
Compromised versions (2)
- 1.0.1
- 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.