VDB

GCVE-110-AUR-2026-001135

GCVE-110-AUR-2026-001135
Advisory Published
Vulnetix · Advisory published June 11, 2026
The Arch User Repository (AUR) package `nodejs-istanbul` was identified as malicious during the June 2026 AUR supply-chain compromise, in which an attacker pushed backdoored PKGBUILDs to roughly 1,900 packages. Building or installing the affected package executed attacker-controlled code. The malicious revision has since been removed from the AUR. Upstream package description: "Yet another JS code coverage tool that computes statement, line, function and branch coverage with module loader hooks to transparently add coverage when running tests. Supports all JS coverage use cases including unit tests, server side functional tests".

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Affected Products

VendorProductVersionsPlatforms
aurnodejs-istanbul* (affected)

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

74,994 records in the GCVE database · Updated July 28, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›