MAL-2026-14362
Malicious code in 10-shardsight-web (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (4c7da64238cd4a48de7b5df200b6b36734be8e33dbc21e3f34a17c7235c94555) index.js is a top-level async IIFE that fetches HTML from the hardcoded, unpinned URL https://bitbucket.org/p2p-alt-public/p2p-emis/raw/main/GameWebSight, replaces document.head and document.body with the fetched markup, and re-creates every <script> tag so the remote JavaScript executes in the consumer's page. The source is a mutable `main` branch on a personal-looking Bitbucket workspace unrelated to any declared publisher, with no integrity check, so whoever controls that repository can push arbitrary JavaScript that runs in the page context of any application that loads this package.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for 10-shardsight-web (npm). Pin to a known-safe version or switch to an alternative.