VYPR

npm · Malicious package advisory

Malware

6-viewsight-web

MAL-2026-14365

Malicious code in 6-viewsight-web (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (96501ebb5a5bb3858767545e256cdcfd23f164f4435c109d206f421771ce6e68)
The package's main module is a self-executing IIFE that fetches HTML from https://bitbucket.org/p2p-alt-public/p2p-emis/raw/main/GameWebSight and injects it into the consuming page's DOM, re-creating each <script> element so its contents execute in the page's JavaScript context. The URL points at the mutable `main` branch with no version pin, hash, or signature check, so whoever controls the `p2p-alt-public/p2p-emis` Bitbucket repository can change the payload at any time and have it run in every application that loads this package. package.json ships with empty author metadata, MIT default, and a generic 'Website loader for remote HTML content' description, and there is no relationship between the publishing npm identity and the Bitbucket account hosting the fetched code.

Compromised versions (2)

  • 1.0.1
  • 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.