VDB
GCVE-110-NPM-2026-033327
GCVE-110-NPM-2026-033327
Advisory Published
[IOC-STIX-MATCH] Malicious URL https://claude.ai/install.sh — referenced in very-happy-cli/scripts.js — matched: console.error(' \x1b[90mmacOS/Linux:\x1b[0m \x1b[36mcurl -fsSL https://claude.ai/install.sh | bash\x1b[0m');
Weaknesses (CWE)
CWE-200Exposure of Sensitive Information to an Unauthorized ActorCWE-506Embedded Malicious Code
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| npm | very-happy-cli | * (affected) | — |
Browse GCVE Records
3,019 records in the GCVE database · Updated September 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.