VDB
GCVE-110-NPM-2026-033572
GCVE-110-NPM-2026-033572
Advisory Published
[JS-HOOK-DECODE-EGRESS-SEQ] npm lifecycle hook decodes a payload (atob/Buffer.from) AND opens a network egress: the canonical npm install-time exfiltration/staged-execution sequence. A benign hook may decode an asset OR contact a registry, but decode+egress together in an install hook is exfiltration/staging.
Weaknesses (CWE)
CWE-506Embedded Malicious CodeCWE-200Exposure of Sensitive Information to an Unauthorized Actor
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| npm | linkgravity | 1.8.0 (affected) | — |
Browse GCVE Records
1,280 records in the GCVE database · Updated September 7, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.