-= Per source details. Do not edit below this line.=-
The package consists of a minimal HTML wrapper (index.html) whose only behavior is to fetch content from a hardcoded, unpinned URL at https://bitbucket.org/p2p-alt-public/p2p-emis/raw/main/GameWebSight, parse the returned HTML, and re-create every <script> element from the response as a live script tag in the host document, causing the fetched JavaScript to execute in the consuming page's origin. The 'raw/main/...' reference is a mutable branch with no commit pin, no hash check, and no signature verification, so the Bitbucket account 'p2p-alt-public' can substitute arbitrary code at any time. package.json has an empty author field and a generic 'Website loader for remote HTML content' description, and main points directly at the wrapper HTML.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-018582",
"versions": [
"1.0.0"
],
"modified_time": "2026-08-23T03:22:09Z",
"sha256": "57b646752857496fc26e1e5d3afab547f62ed43a612fb63fee2878d7fd1b0b09",
"import_time": "2026-08-23T03:25:57.420215008Z",
"source": "amazon-inspector"
},
{
"id": "IN-MAL-2026-018581",
"sha256": "cae23fe6221515577f9b639185cc745675d9711daad4da9fd6d5851aa27c08b5",
"modified_time": "2026-08-23T03:22:00Z",
"versions": [
"1.0.1"
],
"import_time": "2026-08-23T03:25:57.328415328Z",
"source": "amazon-inspector"
}
]
}{
"evidence_files": [
{
"sha256": "0bd895c55a890dbfcb9ca36ef255d88682e1ed12561db7c68379211f8f102278",
"path": "index.js",
"tlsh": "f221ed2c0dab43371b2724a6437bda85753260073009d9d97a8ccb855f04b58cc57fc9"
}
],
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-DKyoTUYC4pZXEGNCoSm7bqzgfUgGblu6jmwUwl5oQGqNCl+Ci+IIRsXwbBpsWL9BXspr19hAKfSUyKvvURzHhA==",
"sha1": "8a1f1e2ec26729e5c43811af1337bbbe852a6545"
},
"filename": "2-loadsight-web-1.0.0.tgz"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/2-loadsight-web/MAL-2026-14363.json"
[
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]