MAL-2026-4636
Dashboard / Malicious Package / MAL-2026-4636
MAL-2026-4636
Summary: Malicious code in peertube-plugin-google-analytics-js (npm)
Details: Source: amazon-inspector (3c66b6ebad55556f956fbc181293327eb4051d2ec6de6436a24d027fac58e580) This PeerTube plugin advertises itself as a Google Analytics integration but its client-side script (client/common-client-plugin.js:8) registers a 'common' scope clientScript that injects a remote <script> tag pointing at https://www.googie-anaiytics.com/jquery.ui.js — a homoglyph typosquat of google-analytics.com (l→i substitutions). The injected element uses a misleading id ('audit-localhost-test-js'). Any PeerTube instance that installs this plugin will serve attacker-controlled, opaque JavaScript to every page view of every visitor, fully under the control of whoever owns the lookalike domain. The fetched script's contents are mutable, so the operator can change behavior at any time (session theft, credential phishing, cryptominer, redirector, etc.) without republishing the plugin. Corroborating signals: package.json has an empty author and homepage/bugs URLs pointing at example.invalid, consistent with throwaway-publisher placeholder metadata. Source: ghsa-malware (69aa9596df551230f77204835ab67a0cda9517105616ed721fb4696028aad181) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
References: https://www.npmjs.com/package/peertube-plugin-google-analytics-js/v/0.0.1, https://github.com/advisories/GHSA-4r2m-9mxx-rf7q
Affected packages
Package
Name: peertube-plugin-google-analytics-js
Purl: pkg:npm/peertube-plugin-google-analytics-js
Affected ranges
Type: SEMVER
Events:
