VDB
GCVE-110-NPM-2026-034233
GCVE-110-NPM-2026-034233
Advisory Published
[JS-HOOK-DECODE-EGRESS-SEQ] npm lifecycle hook decodes a payload (atob/Buffer.from) AND opens a network egress: the canonical npm install-time exfiltration/staged-execution sequence. A benign hook may decode an asset OR contact a registry, but decode+egress together in an install hook is exfiltration/staging.
Weaknesses (CWE)
CWE-506Embedded Malicious CodeCWE-200Exposure of Sensitive Information to an Unauthorized Actor
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| npm | @vanillagreen/pi-background-tasks | 2.1.2 (affected), 2.2.0 (affected) | — |
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.