VDB
GCVE-110-OSM-2026-12195
GCVE-110-OSM-2026-12195
Advisory PublishedCVSS 8.8/10
package.json declares preinstall and postinstall lifecycle scripts that invoke curl against the hardcoded cleartext endpoint http://tko.amgsec.com/depconf/traktis-environment/, sending the output of whoami, hostname, cwd, a timestamp, and a base64-encoded dump of CI/build environment variables matched by the pattern GITHUB_*, CI_PROJECT, JENKINS_URL, BUILD_URL, GITLAB_*, RUNNER_*, HOSTNAME, USER, HOME as query parameters. index.js is a 55-byte placeholder comment and author is listed as 'anonymous'; the manifest lifecycle scripts are the entire functional payload. The name occupies the @traktis scope at version 99.99.2, a version-inflation shape consistent with dependency-confusion resolution against an internal package of the same name. Installing the package on any developer workstation or CI runner automatically transmits build-system identity and any credential-shaped environment variables covered by the grep pattern to a third-party host over plain HTTP.
ENTRY
index.js (default-index: index.js)
- Preinstall Script in package.json: ""preinstall": "curl -s \""
- Postinstall Script in package.json: ""postinstall": "curl -s \""
DESTINATION
- 1 fetched-payload (domains)
(values recorded in verified_iocs)
ADDITIONAL FINDINGS
- Very New NPM Publisher Account
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @traktis/environment | all (affected) | — |
Aliases
Browse GCVE Records
395 records in the GCVE database · Updated September 17, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.