Junglewise Threat Intelligence

sweetalert2 hidden functionality in package initialization

Severity: info · Published 2022-11-23

Technologies: sweetalert2 (npm). Vendors: npm.

Executive brief

sweetalert2 is a popular JavaScript library that provides polished popup dialogs and alerts for web applications. Versions 11.4.9 and above contain hidden code that plays unsolicited audio or video messages unrelated to the library's intended functionality, potentially degrading the user experience and raising concerns about supply chain integrity and maintainer intentions.

Technical details

sweetalert2 versions 11.4.9 and above contain hidden initialization code that outputs audio and/or video messages not documented in the library's API or release notes. The code was intentionally introduced by the maintainer and was absent in versions 11.0.0 through 11.4.8. The hidden functionality executes during normal package loading without explicit developer consent or awareness. While not a traditional security vulnerability that enables unauthorized access, this behavior violates user expectations and library transparency. The vulnerability was resolved in version 11.22.4.

Affected products

  • npm sweetalert2 11.4.9 to 11.22.3

Timeline

  • 2022-11-23: disclosed

References

Related threats