-= Per source details. Do not edit below this line.=-
Package ships a single browser-side IIFE (index.js) that manipulates the DOM (inserts a banner into #root and calls window.widgetSend with a demonstration payload) when loaded as a
{
"malicious-packages-origins": [
{
"id": "GHSA-gq92-h7j2-g9x5",
"import_time": "2026-07-20T00:57:10.765483324Z",
"modified_time": "2026-07-19T23:53:18Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "SEMVER"
}
],
"sha256": "12586eeb5b7eb0c053d90b49fd966fe32f05fe1f551cfd36120de1ce25b34fea",
"source": "ghsa-malware"
},
{
"id": "IN-MAL-2026-013138",
"import_time": "2026-08-05T06:00:46.279052583Z",
"modified_time": "2026-08-05T05:39:22Z",
"sha256": "17ce7f91ce8bd8ab97268072386ec0890f1edc0336138472d428df845041ac5e",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "940f99a65e91b64bd525f4f94cb68198704ca4d6d951496414f595aa157a7edb",
"tlsh": "833120183ce8153435af8ad06377b6853a23902ad000e578fdbdc3255fa87e902637dd"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/zoom-widget-xss-poc-paresh/MAL-2026-10782.json"