@redman89405/my-module@1.1.0
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 11:44 AM UTC
OSV ID
MAL-2026-17336
Ecosystem
npm
Summary
The package ships code.png alongside index.js and exports a function imageToCode that reads a length-prefixed byte stream from the first pixel row of the PNG and passes the decoded string to Function(...)(), an eval-equivalent sink. The executable content is hidden inside an image asset rather than present as readable source, so the code that will run cannot be seen by inspecting the npm tarball. The API is exported alongside trivial hello/add helpers with no documented purpose for image-based code loading, and the author retains the ability to change the payload in future publishes without any visible source diff. The code path relies on browser-only globals (Image, canvas) so it does not fire on Node require; harm requires a consumer application to call imageToCode in a browser context, at which point arbitrary author-supplied JavaScript executes in that page.
Source: amazon-inspector (ee7d38498dcd2e2a3afc4ed3b3a5136cb88e11693ef59fc7676bf35cd89b932c)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.