MAL-2026-14365

    Dashboard / Malicious Package / MAL-2026-14365

    MAL-2026-14365

    Published: 23 Aug 2026Last Modified: 23 Aug 2026

    Summary: Malicious code in 6-viewsight-web (npm)

    Details: Source: amazon-inspector (96501ebb5a5bb3858767545e256cdcfd23f164f4435c109d206f421771ce6e68) The package's main module is a self-executing IIFE that fetches HTML from https://bitbucket.org/p2p-alt-public/p2p-emis/raw/main/GameWebSight and injects it into the consuming page's DOM, re-creating each <script> element so its contents execute in the page's JavaScript context. The URL points at the mutable `main` branch with no version pin, hash, or signature check, so whoever controls the `p2p-alt-public/p2p-emis` Bitbucket repository can change the payload at any time and have it run in every application that loads this package. package.json ships with empty author metadata, MIT default, and a generic 'Website loader for remote HTML content' description, and there is no relationship between the publishing npm identity and the Bitbucket account hosting the fetched code.

    Affected packages

    Package

    Name: 6-viewsight-web

    Purl: pkg:npm/6-viewsight-web

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.1
    1.0.0
    MAL-2026-14365 | CVE-DB