svgson-lite
MAL-2026-6707
npmbackdoor7/1/2026
Description
Malicious code in svgson-lite (npm)
Indicators of Compromise
SHA256 Hashes (7)
083b9db212b14d87917991f5faa63212319efaec6c2b573fa8d0efb1da747572
74d7365a440703b3b3a7dd0486437fedd80cfb6fd4c0d5e636f32385621cb5df
b54d78c3ce0a5c30a8060cc6086a5a5d410fc4ab24442aa93f16475a218e32f4
ceb1026a96918a3f4ed4c7c4f0aa75411c3869f1ad14405174e396b4e67907d2
3af541a1fe8000c1b4aa51ea183d7e780163090d6ca8a2a52dfcd0ebf7f388be
6fb634869b533b95806d632f845ae1a10e6d23e3114f16f0626810367e54817f
745e263630d68551c3f2002b051c37aee9a891e7edec1e2ed2725d27ff66bb65
References (7)
https://www.npmjs.com/package/svgson-lite/v/1.0.1OSVhttps://www.npmjs.com/package/svgson-lite/v/1.0.0OSVhttps://www.npmjs.com/package/svgson-lite/v/1.0.5OSVhttps://www.npmjs.com/package/svgson-lite/v/1.0.6OSVhttps://www.npmjs.com/package/svgson-lite/v/1.0.7OSVhttps://www.npmjs.com/package/svgson-lite/v/1.0.2OSVhttps://www.npmjs.com/package/svgson-lite/v/1.0.4OSV
Details
Ecosystemnpm
Attack Typebackdoor
Published7/1/2026
Quick Actions