Logo
npm

translate-base-font@1.4.2

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17458

Ecosystem

npm

Summary

The package presents itself as a CSS custom-property polyfill for font translation, but its actual behavior is a browser-side code-smuggling vector. payload.css ships ten --base-color-1..--base-color-10 custom properties whose values are hex-byte triplets; the file carries the literal marker Payload for vantamods.online and a __DOMAIN__ placeholder (hex 5f5f444f4d41494e5f5f). At runtime, translate.js reads those CSS variables from the DOM, concatenates the hex bytes into a string, substitutes __DOMAIN__ with the hex-decoded host vantamods.online (sourced from --primary-brand-color), and executes the resulting JavaScript with new ("").constructor.constructor(fromCharCode.apply(null, _b))() — i.e. a Function constructor invocation on attacker-controlled bytes. A hostname guard prevents execution on vantamods.online, localhost, and empty hostnames, so the smuggled code runs only on third-party sites that bundle or CDN-load this package. The advertised polyfill functionality is a cover story: any site shipping this dependency executes arbitrary JavaScript controlled by the maintainer of vantamods.online against every visitor, enabling session theft, credential capture, redirection, or arbitrary DOM manipulation in the site's origin.

Source: amazon-inspector (3b0c647653ce1698d15162d24ea22d9b060d770daf28277f3ce27a0040dda6dc)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.