VDB

GCVE-110-OSM-2026-11932

GCVE-110-OSM-2026-11932
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published September 10, 2026
The package's preinstall lifecycle script (preinstall.js) runs automatically on npm install and issues an HTTP GET to a hardcoded bare-IP endpoint at http://209.126.81.147/etoro-depconf-poce346552f776f/npm/<host>/<user>/<cwd>, embedding os.hostname(), os.userInfo().username, and process.cwd() as URL path segments. The destination is not a first-party or registry host, uses plain HTTP, and the transmission is unconditional and undisclosed. The package name and implausibly high version number (999.0.0) combined with an 'eToro Infrastructure' author string are consistent with a dependency-confusion probe designed to identify internal build environments that resolve the public name in place of a private one. ENTRY preinstall.js (install-hook: node preinstall.js || true) - Install Hook Executes Local JS File in package.json DESTINATION - 1 exfil (custom-c2) (values recorded in verified_iocs) EXFIL - Data Encoding for Exfiltration in preinstall.js: "encodeURIComponent(os.hostname())}/${encodeURIComponent(os.userInfo().username)}..." - Network Request in preinstall.js: "https.get(" - System Information Collection in preinstall.js: "os.userInfo()" - Suspicious Domain in preinstall.js: "http://209.126.81.147" PAYLOAD FILES preinstall.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownetoro-cashoutall (affected)

References

advisory
vendor

Browse GCVE Records

506 records in the GCVE database · Updated September 11, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›