VDB

GCVE-110-OSM-2026-11088

GCVE-110-OSM-2026-11088
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published August 24, 2026
The package's preinstall lifecycle script fires automatically on npm install and collects the installer's OS username, hostname, current working directory, and the enclosing project's package.json name/author/version (obtained by walking up parents of __dirname). The JSON payload is hex-encoded, split into 60-character chunks, and leaked as DNS labels via dns.lookup queries under the hardcoded subdomain da5u87oh92rc72pp1dngqfc6hp8gwshm6.o.jgl.red, with a fallback DNS query on error. The chunked hex-over-DNS transport is a covert-channel technique that evades many egress filters. Package metadata is minimal (placeholder main, empty author) and inconsistent with any legitimate logging library, matching a dependency-confusion reconnaissance beacon pattern. ENTRY preinstall.js (install-hook: node preinstall.js) - Install Hook Executes Local JS File in package.json EXFIL - System Information Collection in preinstall.js: "os.userInfo()" - DNS Lookup in preinstall.js: "dns.lookup(" ADDITIONAL FINDINGS - Brand New Package - Very New NPM Publisher Account PAYLOAD FILES preinstall.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownmanticore-logall (affected)

References

advisory
vendor

Browse GCVE Records

1,469 records in the GCVE database · Updated September 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›