Description
A dependency confusion vulnerability was identified in the Motive web application (app.gomotive.com). A JavaScript bundle served at the following URL references an internal/private npm package — videojs-v8 — that has no corresponding entry on the public npm registry:
https://app.gomotive.com/en-US/4836.aa94c96528a199d39fc7.js
The source map embedded in the response reveals the internal package path:
webpack://./node_modules/videojs-v8/dist/video-js.css
Because videojs-v8 is not registered on https://registry.npmjs.org/videojs-v8, an attacker can publish a malicious package under that name on the public npm registry with a higher version number. If a developer or CI/CD pipeline runs npm install without a private registry lock, npm's default resolution will prefer the public registry version, causing the malicious package to be installed instead.
Impact
An attacker can claim the unclaimed videojs-v8 package on the public npm registry and inject malicious code that executes automatically during npm install in developer or CI/CD environments. This can lead to full RCE on build infrastructure, secret/credential exfiltration, and poisoned production artifacts being deployed to Motive's platform.
Recommendation
Immediately register videojs-v8 on npmjs.org as a placeholder to prevent hostile takeover, and migrate the package to a scoped name (e.g., @motive/videojs-v8) long-term. Enforce private registry resolution via .npmrc so internal packages are never resolved from the public registry. Additionally, disable webpack source maps in production builds to prevent leaking internal package names and paths.
Reduced test case
https://abc.com/en-US/4836.aa94c96528a199d39fc7.js
Steps to reproduce
- Fetch the public bundle to confirm the internal package reference
- In the response body, locate the embedded source map referencing:
"webpack://./node_modules/videojs-v8/dist/video-js.css"
- Confirm the package is unclaimed on npm:
GET https://registry.npmjs.org/videojs-v8
Errors
No response
What version of Video.js are you using?
v8
Video.js plugins used.
No response
What browser(s) including version(s) does this occur with?
Chrome
What OS(es) and version(s) does this occur with?
Mac
Description
A dependency confusion vulnerability was identified in the Motive web application (app.gomotive.com). A JavaScript bundle served at the following URL references an internal/private npm package — videojs-v8 — that has no corresponding entry on the public npm registry:
https://app.gomotive.com/en-US/4836.aa94c96528a199d39fc7.js
The source map embedded in the response reveals the internal package path:
webpack://./node_modules/videojs-v8/dist/video-js.css
Because videojs-v8 is not registered on https://registry.npmjs.org/videojs-v8, an attacker can publish a malicious package under that name on the public npm registry with a higher version number. If a developer or CI/CD pipeline runs npm install without a private registry lock, npm's default resolution will prefer the public registry version, causing the malicious package to be installed instead.
Impact
An attacker can claim the unclaimed videojs-v8 package on the public npm registry and inject malicious code that executes automatically during npm install in developer or CI/CD environments. This can lead to full RCE on build infrastructure, secret/credential exfiltration, and poisoned production artifacts being deployed to Motive's platform.
Recommendation
Immediately register videojs-v8 on npmjs.org as a placeholder to prevent hostile takeover, and migrate the package to a scoped name (e.g., @motive/videojs-v8) long-term. Enforce private registry resolution via .npmrc so internal packages are never resolved from the public registry. Additionally, disable webpack source maps in production builds to prevent leaking internal package names and paths.
Reduced test case
https://abc.com/en-US/4836.aa94c96528a199d39fc7.js
Steps to reproduce
"webpack://./node_modules/videojs-v8/dist/video-js.css"GET https://registry.npmjs.org/videojs-v8Errors
No response
What version of Video.js are you using?
v8
Video.js plugins used.
No response
What browser(s) including version(s) does this occur with?
Chrome
What OS(es) and version(s) does this occur with?
Mac