Malicious code in 3-buildsight-web (npm)
The 3-buildsight-web npm package versions 1.0.0 and 1.0.1 contain malicious code that fetches and executes remote JavaScript from an unpinned Bitbucket URL. This remote code is injected into the DOM and executed with the full privileges of the consuming page, allowing whoever controls the Bitbucket branch to run arbitrary code in any application importing this package.
AI Analysis
Technical Summary
The 3-buildsight-web package's main entry point includes a top-level immediately-invoked function expression (IIFE) that, upon module load, fetches HTML content from a hardcoded Bitbucket raw URL on the mutable 'main' branch. The fetched HTML is parsed and injected into the DOM, with <script> elements recreated and appended to the document body, causing execution of remote JavaScript in the context of the consuming page. The reference to the remote code is unpinned, meaning it does not specify a commit hash, tag, or integrity check, allowing the remote content to be changed at any time by whoever controls the Bitbucket workspace 'p2p-alt-public'. This results in arbitrary code execution with the privileges of the page using the package.
Potential Impact
Any application importing the affected versions of 3-buildsight-web will execute arbitrary JavaScript controlled by the attacker hosting the Bitbucket repository. This can lead to full compromise of the application's client-side environment, including data theft, session hijacking, or further malicious actions within the user's browser context.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately stop using versions 1.0.0 and 1.0.1 of 3-buildsight-web. Avoid importing this package until a trusted, verified version is released. Consider auditing dependencies for similar unpinned remote code references. Monitor vendor advisories for updates or official fixes.
Malicious code in 3-buildsight-web (npm)
Description
The 3-buildsight-web npm package versions 1.0.0 and 1.0.1 contain malicious code that fetches and executes remote JavaScript from an unpinned Bitbucket URL. This remote code is injected into the DOM and executed with the full privileges of the consuming page, allowing whoever controls the Bitbucket branch to run arbitrary code in any application importing this package.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 3-buildsight-web package's main entry point includes a top-level immediately-invoked function expression (IIFE) that, upon module load, fetches HTML content from a hardcoded Bitbucket raw URL on the mutable 'main' branch. The fetched HTML is parsed and injected into the DOM, with <script> elements recreated and appended to the document body, causing execution of remote JavaScript in the context of the consuming page. The reference to the remote code is unpinned, meaning it does not specify a commit hash, tag, or integrity check, allowing the remote content to be changed at any time by whoever controls the Bitbucket workspace 'p2p-alt-public'. This results in arbitrary code execution with the privileges of the page using the package.
Potential Impact
Any application importing the affected versions of 3-buildsight-web will execute arbitrary JavaScript controlled by the attacker hosting the Bitbucket repository. This can lead to full compromise of the application's client-side environment, including data theft, session hijacking, or further malicious actions within the user's browser context.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately stop using versions 1.0.0 and 1.0.1 of 3-buildsight-web. Avoid importing this package until a trusted, verified version is released. Consider auditing dependencies for similar unpinned remote code references. Monitor vendor advisories for updates or official fixes.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14364
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a8af9a3acd9273b49f32ed9
Added to database: 08/23/2026, 13:46:11 UTC
Last enriched: 08/23/2026, 13:49:16 UTC
Last updated: 08/23/2026, 23:11:13 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.