CyberSecurityBoardThreat Intel · CVEs · Products
Malware

G2: Remote Script Loader in npm Proxy Campaign

July 14, 2026

A remote script loader module found in the malicious npm packages, which fetches JavaScript from a GitHub repository through the jsDelivr CDN without Subresource Integrity checks, allowing arbitrary code execution in visitors' browsers.