opiumisbest@1.1.0
Malicious code in opiumisbest (npm)
Analysis
The package ships an SVG (index.svg) that embeds an HTML page. When the SVG is opened in a browser, an inline script fetches a remote loader.js from a jsDelivr-hosted GitHub repository (TongSherbet/storage) and injects it as a script tag, executing attacker-controlled code in the page context. A bundled service worker (sw.js) performs the same remote-code load via importScripts from the same CDN. The remote payload is fetched fresh each hour (cache-busted with a timestamp query) from the following CDN mirrors: hxxps://cdn[.]jsdelivr[.]net/gh/TongSherbet/storage/, hxxps://quantil[.]jsdelivr[.]net/gh/TongSherbet/storage/, hxxps://fastly[.]jsdelivr[.]net/gh/TongSherbet/storage/, hxxps://testingcf[.]jsdelivr[.]net/gh/TongSherbet/storage/, hxxps://gcore[.]jsdelivr[.]net/gh/TongSherbet/storage/, hxxps://originfastly[.]jsdelivr[.]net/gh/TongSherbet/storage/, hxxps://jsdelivr[.]b-cdn[.]net/gh/TongSherbet/storage/. The package has no install-time lifecycle hooks; the malicious behaviour is the browser-side remote script injection.
- analyzed by
- Leitwacht
- first seen
- Aug 31, 2026, 02:45 AM
- analyzed
- Aug 31, 2026, 02:46 AM
Related advisories
- eslint-prettier-js@0.0.1
- originaldevelopmentstelemetry@1.2.2
- developmentstelemetry@1.0.1
- node-request-utils@1.0.0
- mfaatest@1.0.0
- mfafix@1.0.0
- cbc97b7a@1.1787999998.0
- exprss-helmet@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.