MAL-2026-17313

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/pixsvg/MAL-2026-17313.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17313
Published
2026-09-30T01:48:51Z
Modified
2026-09-30T03:00:04Z
Summary
Malicious code in pixsvg (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (23f6989954f196f485ff049ef7dc22bb800a57187e6bdc8bd0e002ed4bbc1db7)

The pixsvg module exports fetchDataFromSvg(svgData), which scans the input SVG for a comment of the form , reassembles the binary-encoded 1/0 sequence into a JavaScript string via binaryToData (parseInt(chunk,2) + String.fromCharCode), and passes the reconstructed string to eval(). The helper is exported on the package's public surface (module.exports.fetchDataFromSvg) but is not documented in the README and is unrelated to the advertised SVG image pipeline. Any consumer application that feeds externally-supplied SVG content through this exported function will execute attacker-controlled JavaScript in the host process. The binary-encoding-then-eval shape is a deliberate covert execution channel with no legitimate role in an image-processing library.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020794",
            "import_time":  "2026-09-30T02:52:56.995517197Z",
            "modified_time":  "2026-09-30T01:48:51Z",
            "sha256":  "23f6989954f196f485ff049ef7dc22bb800a57187e6bdc8bd0e002ed4bbc1db7",
            "source":  "amazon-inspector",
            "versions":  [
                "0.2.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / pixsvg

Package

Affected ranges

Affected versions

0.*
0.2.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "dist/commonjs/svg.js",
            "sha256":  "c2aa01b4c61279ea675500644839019cbf754a60a347f776e4e3529f2e92f2b3",
            "tlsh":  "4332105829f32051429371b9978f988c757ee513374ece95ba1c83e12f50478eaf3ba8"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "pixsvg-0.2.0.tgz",
            "hashes":  {
                "sha1":  "3d8d5c711f27e6ffac39e401e2381a9118614d3f",
                "sha512_sri":  "sha512-GnOGxdd2SZldUsPp90F0mpbyJhJZ2RIxpcQtnTgEGewBC79DJPexlaBZHFW1vZY8CAZjy+s5wr56gyTmmRBt4Q=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/pixsvg/MAL-2026-17313.json"