Logo
npm

pixsvg@0.2.0

Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC

Malicious

OSV ID

MAL-2026-17313

Ecosystem

npm

Summary

The pixsvg module exports fetchDataFromSvg(svgData), which scans the input SVG for a comment of the form <!--HIDDEN_JS:([01]+)-->, reassembles the binary-encoded 1/0 sequence into a JavaScript string via binaryToData (parseInt(chunk,2) + String.fromCharCode), and passes the reconstructed string to eval(). The helper is exported on the package's public surface (module.exports.fetchDataFromSvg) but is not documented in the README and is unrelated to the advertised SVG image pipeline. Any consumer application that feeds externally-supplied SVG content through this exported function will execute attacker-controlled JavaScript in the host process. The binary-encoding-then-eval shape is a deliberate covert execution channel with no legitimate role in an image-processing library.

Source: amazon-inspector (23f6989954f196f485ff049ef7dc22bb800a57187e6bdc8bd0e002ed4bbc1db7)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.