-= Per source details. Do not edit below this line.=-
The pixsvg module exports fetchDataFromSvg(svgData), which scans the input SVG for a comment of the form , reassembles the binary-encoded 1/0 sequence into a JavaScript string via binaryToData (parseInt(chunk,2) + String.fromCharCode), and passes the reconstructed string to eval(). The helper is exported on the package's public surface (module.exports.fetchDataFromSvg) but is not documented in the README and is unrelated to the advertised SVG image pipeline. Any consumer application that feeds externally-supplied SVG content through this exported function will execute attacker-controlled JavaScript in the host process. The binary-encoding-then-eval shape is a deliberate covert execution channel with no legitimate role in an image-processing library.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020794",
"import_time": "2026-09-30T02:52:56.995517197Z",
"modified_time": "2026-09-30T01:48:51Z",
"sha256": "23f6989954f196f485ff049ef7dc22bb800a57187e6bdc8bd0e002ed4bbc1db7",
"source": "amazon-inspector",
"versions": [
"0.2.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "dist/commonjs/svg.js",
"sha256": "c2aa01b4c61279ea675500644839019cbf754a60a347f776e4e3529f2e92f2b3",
"tlsh": "4332105829f32051429371b9978f988c757ee513374ece95ba1c83e12f50478eaf3ba8"
}
],
"package_integrity": [
{
"filename": "pixsvg-0.2.0.tgz",
"hashes": {
"sha1": "3d8d5c711f27e6ffac39e401e2381a9118614d3f",
"sha512_sri": "sha512-GnOGxdd2SZldUsPp90F0mpbyJhJZ2RIxpcQtnTgEGewBC79DJPexlaBZHFW1vZY8CAZjy+s5wr56gyTmmRBt4Q=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/pixsvg/MAL-2026-17313.json"