-= Per source details. Do not edit below this line.=-
This PeerTube plugin advertises itself as a Google Analytics integration but its client-side script (client/common-client-plugin.js:8) registers a 'common' scope clientScript that injects a remote
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-004246",
"import_time": "2026-05-26T05:52:13.689791439Z",
"modified_time": "2026-05-22T18:46:45Z",
"sha256": "3c66b6ebad55556f956fbc181293327eb4051d2ec6de6436a24d027fac58e580",
"source": "amazon-inspector",
"versions": [
"0.0.1"
]
},
{
"id": "GHSA-4r2m-9mxx-rf7q",
"import_time": "2026-06-01T17:03:32.536865585Z",
"modified_time": "2026-06-01T15:33:38Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "SEMVER"
}
],
"sha256": "69aa9596df551230f77204835ab67a0cda9517105616ed721fb4696028aad181",
"source": "ghsa-malware"
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "client/common-client-plugin.js",
"sha256": "b65a877a06feb26babbdbd7a4cd10aba9ba70c41f8a469f268a7bc17b1b4d6a9",
"tlsh": "83e026aaacfac5325ba575af247ed378761360193402f8858eecca956041fed9c22d0d"
},
{
"path": "package.json",
"sha256": "a95dc007c3016fa7d60dd44f9af3b13f7fc7c4a51c02ba11a7ef448189b0ce66",
"tlsh": "1801c00c9a649c7345d90776b2289685d2384a8359ddfc1577df010c4f4ca6b44ffd8c"
}
],
"package_integrity": [
{
"filename": "peertube-plugin-google-analytics-js-0.0.1.tgz",
"hashes": {
"sha1": "94f35092c029dd6f31e9630fe8b0ba4aa767cc22",
"sha512_sri": "sha512-sxtty9n7JG12XSYHpHb6gmiAev2wm8jYamqmXUHr8Iv+/G+VXjjUWd+RqKyuV9OmAeiRA9C/7u4E9jSnDAQPBQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/peertube-plugin-google-analytics-js/MAL-2026-4636.json"