npm

10-shardsight-web @1.0.1

Vulnerability report · Last retrieved from osv.dev August 23, 2026 at 10:13 AM UTC

Malicious

OSV ID

MAL-2026-14362

Ecosystem

npm

Summary

index.js is a top-level async IIFE that fetches HTML from the hardcoded, unpinned URL https://bitbucket.org/p2p-alt-public/p2p-emis/raw/main/GameWebSight, replaces document.head and document.body with the fetched markup, and re-creates every <script> tag so the remote JavaScript executes in the consumer's page. The source is a mutable main branch on a personal-looking Bitbucket workspace unrelated to any declared publisher, with no integrity check, so whoever controls that repository can push arbitrary JavaScript that runs in the page context of any application that loads this package.

Source: amazon-inspector (4c7da64238cd4a48de7b5df200b6b36734be8e33dbc21e3f34a17c7235c94555)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.