VDB
GCVE-110-OSM-2026-10231
GCVE-110-OSM-2026-10231
Advisory PublishedCVSS 8.8/10
This package is consistent with a dependency-confusion implant that runs on install and phones home to a custom C2. The `postinstall` hook executes `scripts/check-env.js`, which collects `process.platform`, `process.arch`, and `process.version` and sends them via `http.request` as a POST to the attacker-controlled IP address. This dependency confusion attempt appears to target Azure and extract sensitive cloud environment variables via the DGN_SRC_ENDPOINT endpoint.
ENTRY
scripts/check-env.js (install-hook: node scripts/check-env.js)
- Install Hook Executes Local JS File in package.json
DESTINATION
- 2 exfil (custom-c2)
(values recorded in verified_iocs)
EXFIL
- Network Request in scripts/check-env.js: "http.request("
- System Information Collection in scripts/check-env.js: "process.platform"
ADDITIONAL FINDINGS
- Brand New Package
- Very New NPM Publisher Account
PAYLOAD FILES
scripts/check-env.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @dgn-src-click-to-pay-org/srcdcfreleasecert | all (affected) | — |
Aliases
References
Browse GCVE Records
69,369 records in the GCVE database · Updated August 25, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.