VDB
EN

MAL-2026-14364

Malicious code in 3-buildsight-web (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (ed2d8b62e8d6f475efc170e1f26783037acc358eac7f32153110f29ecb415545) The package's main entry contains a top-level IIFE that runs on module load and fetches content from a hardcoded Bitbucket raw URL, https://bitbucket.org/p2p-alt-public/p2p-emis/raw/main/GameWebSight, on the mutable `main` branch. The parsed HTML is injected into the DOM and <script> nodes are re-created and appended to document.body, causing the remote JavaScript to execute in the consuming page's context. The reference is unpinned (no commit hash, tag, or integrity check), and the Bitbucket workspace (p2p-alt-public) is not aligned with any recognizable publisher. Whoever controls that branch can substitute arbitrary JavaScript at any time; each load of any application that imports this package will execute whatever bytes the branch currently serves, with the full privileges of that page.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / 3-buildsight-web

No fixed version published yet for 3-buildsight-web (npm). Pin to a known-safe version or switch to an alternative.

참고