VDB

GCVE-110-NPM-2026-033327

GCVE-110-NPM-2026-033327
Advisory Published
Vulnetix · Advisory published July 31, 2026
[IOC-STIX-MATCH] Malicious URL https://claude.ai/install.sh — referenced in very-happy-cli/scripts.js — matched: console.error(' \x1b[90mmacOS/Linux:\x1b[0m \x1b[36mcurl -fsSL https://claude.ai/install.sh | bash\x1b[0m');

Weaknesses (CWE)

CWE-200Exposure of Sensitive Information to an Unauthorized ActorCWE-506Embedded Malicious Code

Affected Products

VendorProductVersionsPlatforms
npmvery-happy-cli* (affected)

References

advisory
web

Browse GCVE Records

3,019 records in the GCVE database · Updated September 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›