-= Per source details. Do not edit below this line.=-
index.js is a top-level async IIFE that fetches HTML from the hardcoded, unpinned URL https://bitbucket.org/p2p-alt-public/p2p-emis/raw/main/GameWebSight, replaces document.head and document.body with the fetched markup, and re-creates every
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-018583",
"import_time": "2026-08-23T03:25:57.511148091Z",
"modified_time": "2026-08-23T03:22:18Z",
"sha256": "2cd2de707f62fd397a774d1ce56fa6e2a431c83a69b637c7d6675203b0f657dc",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
},
{
"id": "IN-MAL-2026-018584",
"import_time": "2026-08-23T03:25:57.604515961Z",
"modified_time": "2026-08-23T03:22:26Z",
"sha256": "4c7da64238cd4a48de7b5df200b6b36734be8e33dbc21e3f34a17c7235c94555",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.html",
"sha256": "7ca3f9365fb88e816da0eb8d7fa388f2752d37ad8b650fb3c7224f260a204154",
"tlsh": "8631eb2c0dab83371b222496537bd689753250073005d9d97acccb855f44b59cc47fc9"
}
],
"package_integrity": [
{
"filename": "10-shardsight-web-1.0.1.tgz",
"hashes": {
"sha1": "248b9b1222f8630b2fbe7d57f2a5c5395ab54f74",
"sha512_sri": "sha512-7rfCXIb50ndV8QkB0pA7TTMH1YI7CEcuSZKaAp8dku95NXu+wjVyytp3gQUvgMqLfu1dgRhZvYqAa8PPNuouiQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/10-shardsight-web/MAL-2026-14362.json"