svgson-lite@1.0.4
Malicious code in svgson-lite (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1102 · Web ServiceT1071.001 · Web Protocols
Analysis
svgson-lite@1.0.4 is a trojanized SVG helper that contains a remote code execution backdoor. The exported getPlugin() function fetches content from hxxps://shorturl[.]at/147uq and executes it via eval(), allowing the remote server to run arbitrary JavaScript code in the context of any application that imports this package. The backdoor is hidden among legitimate SVG utility functions (isSvg, getSvgSize, removeComments, etc.).
- analyzed by
- Leitwacht
- first seen
- Jul 1, 2026, 05:48 PM
- analyzed
- Jul 1, 2026, 08:20 PM
Related advisories
- ddok-modal@1.0.0
- tailwindcss-effector@1.7.0
- search-from-feed@999.0.0
- ordered-btree@3.2.2
- xboxauthwrapper@3.9.8
- thienc-cdn@1.0.0
- system-drive@1.0.0
- sqrt-bn-enhanced@2.0.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.