Malicious Package Affecting isite package, versions =2026.8.26=2026.7.2=2026.7.1=2026.6.1=2026.4.5=2026.4.4=2026.4.3=2026.4.2=2026.4.1=2026.1.2=2026.1.1=2025.12.1=2025.11.4=2025.11.3=2025.11.2=2025.11.1=2025.10.4=2025.10.3=2025.10.2=2025.10.1=2025.9.3=2025.9.2=2025.9.1=2025.8.8=2025.8.7=2025.8.6=2025.8.5=2025.8.4=2025.8.3=2025.8.2=2025.8.1=2025.7.2=2025.7.1=2025.5.1=2025.1.20=2025.1.18=2025.1.17=2025.1.16=2025.1.15=2025.1.13=2025.1.12=2025.1.11=2025.1.10=2025.1.6=2025.1.5=2025.1.4=2025.1.3=2025.1.2=2025.1.1=2024.12.6=2024.12.5=2024.12.4=2024.12.3=2024.12.2=2024.12.1=2024.10.3=2024.10.2=2024.10.1=2024.9.2=2024.9.1=2024.8.23=2024.8.22=2024.8.21=2024.8.20=2024.8.19=2024.8.18=2024.8.17=2024.8.16=2024.8.15=2024.8.14=2024.8.13=2024.8.12=2024.8.11=2024.8.10=2024.8.9=2024.8.7=2024.8.6=2024.8.5=2024.8.3=2024.8.2=2024.6.9=2024.6.7=2024.6.5=2024.6.4=2024.6.3=2024.6.2=2024.5.16=2024.5.15=2024.1.1=2023.12.22=2023.12.21=2023.12.20=2023.12.19=2023.12.18=2023.12.17=2023.12.16=2023.12.15=2023.12.2=2023.12.1=2023.11.20


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Attacked

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-ISITE-19314193
  • published27 Aug 2026
  • disclosed26 Aug 2026
  • creditUnknown

Introduced: 26 Aug 2026

New Malicious CVE NOT AVAILABLE CWE-506  (opens in a new tab)

How to fix?

Avoid using all malicious instances of the isite package.

Overview

isite is a malicious package. This package contains malicious code, and its content was removed from the official package manager. While this package might be attempting to impersonate a valid organization, there is no connection between that organization and this package authorship.

CVSS Base Scores

version 4.0
version 3.1