VDB

GCVE-110-OSM-2026-10518

GCVE-110-OSM-2026-10518
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published August 13, 2026
This looks like a reverse-shell or payload-delivery package published by a burner npm account, not a legitimate library: the operational URL points to an ngrok-free.dev tunnel and the static analyzer explicitly matched the reverse-shell setup combo. The package.json contains a postinstall node -e hook, which is a common persistence/execution vector for pulling and running remote code during installation. Given the brand-new publisher identity, minimal metadata, and fetched-payload IOC. The most plausible attacker model is a supply-chain delivery implant intended to execute a remote payload on install. ENTRY - Postinstall Script in package.json: ""postinstall": "node -e \"" DESTINATION - 2 fetched-payload (urls, domains) (values recorded in verified_iocs) ADDITIONAL FINDINGS - Ngrok Tunneling Service in package.json: "ngrok-free.dev" - Brand New Package - Very New NPM Publisher Account

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownnotafollowerall (affected)

References

advisory
vendor

Browse GCVE Records

417 records in the GCVE database · Updated August 26, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›