VDB
GCVE-110-OSM-2026-11247
GCVE-110-OSM-2026-11247
Advisory PublishedCVSS 9.6/10
Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Judge assessment: This looks like a credential/exfil loader masquerading as a tiny npm package: the default entrypoint `index.js` contains a base64 blob that decodes to a JSON payload pointing at `https://api.dq87771.com`, which is not a legitimate package dependency pattern. The recovered security-holding content and the OSV malware advisory `MAL-2026-14569` align with a compromised-package attacker model, not a benign library. The package metadata is also burner-like (`brand-new-package`, no repository, no description, single package under a fresh account), which strongly fits a malicious dropper published to harvest secrets or beacon out to a remote controller.
ENTRY
index.js (default-index: index.js)
ADDITIONAL FINDINGS
- Brand New Package
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @hd-team/app-dnpkg-beta | all (affected) | — |
Aliases
Browse GCVE Records
831 records in the GCVE database · Updated September 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.