MAL-2026-10782

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/zoom-widget-xss-poc-paresh/MAL-2026-10782.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-10782
Aliases
  • GHSA-gq92-h7j2-g9x5
Published
2026-07-19T23:53:18Z
Modified
2026-08-05T06:36:44Z
Summary
Malicious code in zoom-widget-xss-poc-paresh (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (17ce7f91ce8bd8ab97268072386ec0890f1edc0336138472d428df845041ac5e)

Package ships a single browser-side IIFE (index.js) that manipulates the DOM (inserts a banner into #root and calls window.widgetSend with a demonstration payload) when loaded as a

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "GHSA-gq92-h7j2-g9x5",
            "import_time": "2026-07-20T00:57:10.765483324Z",
            "modified_time": "2026-07-19T23:53:18Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "SEMVER"
                }
            ],
            "sha256": "12586eeb5b7eb0c053d90b49fd966fe32f05fe1f551cfd36120de1ce25b34fea",
            "source": "ghsa-malware"
        },
        {
            "id": "IN-MAL-2026-013138",
            "import_time": "2026-08-05T06:00:46.279052583Z",
            "modified_time": "2026-08-05T05:39:22Z",
            "sha256": "17ce7f91ce8bd8ab97268072386ec0890f1edc0336138472d428df845041ac5e",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / zoom-widget-xss-poc-paresh

Package

Name
zoom-widget-xss-poc-paresh
View open source insights on deps.dev
Purl
pkg:npm/zoom-widget-xss-poc-paresh

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "index.js",
            "sha256": "940f99a65e91b64bd525f4f94cb68198704ca4d6d951496414f595aa157a7edb",
            "tlsh": "833120183ce8153435af8ad06377b6853a23902ad000e578fdbdc3255fa87e902637dd"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/zoom-widget-xss-poc-paresh/MAL-2026-10782.json"