VDB

GCVE-110-OSM-2026-11431

GCVE-110-OSM-2026-11431
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published September 1, 2026
This package is a dependency confusion attempt and its own description reads "A trial module. Harmless and personal test use only". The index.js file says that that this package is a Dependency Confusion Research Project, but this package does FAR more than a normal PoC does, exfiling everything it can The package.json file calls a preinstall script that in turn executes the index.js file where the payload is. While this author tries to make this package seem like a harmless proof of concept, it is anything but that. This package is an environment and infostealer and specifically targets ssh keys, AWS metadata/credentials, continuous integration creds from multiple platforms, network info, docker environments, kubernetes environments, git config and credentials. Then the script looks for common scanner script files and exfiltrates those. Then it lists all files in /root, /opt, /tmp and / and exfiltrates those. Then it grabs every environment variable on the compromised system and exfils that too. This is the most comprehensive clear text javascript stealer we've seen in a while.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownreact-hook-form-5all (affected)

References

advisory
vendor

Browse GCVE Records

805 records in the GCVE database · Updated September 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›