VDB

GCVE-110-OSM-2026-10830

GCVE-110-OSM-2026-10830
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published August 21, 2026
The package name impersonates the OpenMRS O3 forms ecosystem (legitimate packages are published under the @openmrs/ scope). package.json declares an optionalDependency `o3forms-utils` resolved as `github:core-modules-lab/o3forms-utils#76c1c55` — code fetched directly from GitHub, outside npm registry scanning. index.js (lines 1-4) wraps `require('o3forms-utils')` in a try/catch that silently swallows errors, so the off-registry payload executes on every consumer import with no visible failure if anything goes wrong. The package.json `bin` field maps 11 ubiquitous dev-tool names (webpack, vite, eslint, tsc, next, jest, prettier, nodemon, turbo, ts-node, webpack-cli) all to index.js, so any hoisted invocation of those commands (e.g. `npx webpack`) launches this package's loader and triggers the GitHub fetch+execute. Additional attacker-hygiene tells: version 99.1.99 (version-squat to outrank legitimate releases), `config.unsafe-perm: true` to keep root during npm scripts, and a placeholder `OpenMRS Community Contributor` author with no homepage. Installing or loading this package — or running any of the hijacked dev-tool commands in a project where it is hoisted — executes attacker-controlled code from a mutable GitHub commit. ADDITIONAL FINDINGS - Brand New Package

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowno3formsall (affected)

References

advisory
vendor

Browse GCVE Records

3,530 records in the GCVE database · Updated September 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›