rai6jaisahthaghee5ou-loader-package@1.0.0
Vulnerability report · Last retrieved from osv.dev September 28, 2026 at 11:09 PM UTC
OSV ID
MAL-2026-17238
Ecosystem
npm
Summary
The package's main module is an IIFE that injects a <script> element pointing at the hardcoded URL https://nee1ahnaw7.xsses.link and appends it to the document, causing whatever JavaScript that host serves to execute in the caller's page context. The destination is unpinned, opaque, unrelated to the package's declared identity or publisher, and the host name aligns with XSS/payload delivery infrastructure. Any application that bundles this dependency will fetch and execute attacker-controlled JavaScript at runtime, granting full code execution within the app's origin — enabling credential/session theft, arbitrary DOM manipulation, and further payload staging.
Source: amazon-inspector (6de53fbd264f685e033789fe5929c63f322366219d80707ec419a48a85e253c9)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.