VDB
GCVE-110-OSM-2026-11431
GCVE-110-OSM-2026-11431
Advisory PublishedCVSS 8.8/10
This package is a dependency confusion attempt and its own description reads "A trial module. Harmless and personal test use only". The index.js file says that that this package is a Dependency Confusion Research Project, but this package does FAR more than a normal PoC does, exfiling everything it can
The package.json file calls a preinstall script that in turn executes the index.js file where the payload is. While this author tries to make this package seem like a harmless proof of concept, it is anything but that. This package is an environment and infostealer and specifically targets ssh keys, AWS metadata/credentials, continuous integration creds from multiple platforms, network info, docker environments, kubernetes environments, git config and credentials. Then the script looks for common scanner script files and exfiltrates those. Then it lists all files in /root, /opt, /tmp and / and exfiltrates those. Then it grabs every environment variable on the compromised system and exfils that too. This is the most comprehensive clear text javascript stealer we've seen in a while.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | react-hook-form-5 | all (affected) | — |
Aliases
Browse GCVE Records
805 records in the GCVE database · Updated September 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.