Malicious code in cors-security (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (b1cff2c95bb175e36d5cb7a6e4880ed0f8816cbfb1dc7acef5d8173cf2cc40bb) The CommonJS entry point of [email protected] exposes a getPlugin() API that issues an HTTPS GET to the hardcoded host workconfig.vercel.app and passes the response body directly to new Function('require', data)(require), running attacker-controlled JavaScript inside the consumer's Node process with access to require. TLS certificate verification is disabled on that request (rejectUnauthorized: false). The remote-loader code is present only in the CJS entry and absent from the ESM variant, and does not relate to the package's advertised SVG-utility purpose (name svgcraft, description "Professional zero-dependency SVG utilities"). Any consumer that requires the package and invokes the returned function executes whatever content the operator of workconfig.vercel.app serves at that moment.
Malicious code in cors-security (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (b1cff2c95bb175e36d5cb7a6e4880ed0f8816cbfb1dc7acef5d8173cf2cc40bb) The CommonJS entry point of [email protected] exposes a getPlugin() API that issues an HTTPS GET to the hardcoded host workconfig.vercel.app and passes the response body directly to new Function('require', data)(require), running attacker-controlled JavaScript inside the consumer's Node process with access to require. TLS certificate verification is disabled on that request (rejectUnauthorized: false). The remote-loader code is present only in the CJS entry and absent from the ESM variant, and does not relate to the package's advertised SVG-utility purpose (name svgcraft, description "Professional zero-dependency SVG utilities"). Any consumer that requires the package and invokes the returned function executes whatever content the operator of workconfig.vercel.app serves at that moment.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12357
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a735744bf8831d539159c91
Added to database: 08/05/2026, 15:31:16 UTC
Last updated: 08/05/2026, 15:31:16 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.