VDB
Sign up
—

MAL-2026-17238

Malicious code in rai6jaisahthaghee5ou-loader-package (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (6de53fbd264f685e033789fe5929c63f322366219d80707ec419a48a85e253c9) The package's main module is an IIFE that injects a <script> element pointing at the hardcoded URL https://nee1ahnaw7.xsses.link and appends it to the document, causing whatever JavaScript that host serves to execute in the caller's page context. The destination is unpinned, opaque, unrelated to the package's declared identity or publisher, and the host name aligns with XSS/payload delivery infrastructure. Any application that bundles this dependency will fetch and execute attacker-controlled JavaScript at runtime, granting full code execution within the app's origin — enabling credential/session theft, arbitrary DOM manipulation, and further payload staging.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/rai6jaisahthaghee5ou-loader-package

No fixed version published yet for rai6jaisahthaghee5ou-loader-package (npm). Pin to a known-safe version or switch to an alternative.

References