VDB

GCVE-110-OSM-2026-12435

GCVE-110-OSM-2026-12435
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published September 21, 2026
chat-adapter-matrix@99.99.99 executes server.js from every npm lifecycle hook (preinstall, install, postinstall, prepare, prepublish, preprepare, postprepare) and from the main module. server.js issues an HTTPS GET to the hardcoded webhook host eo8f3m3ho26a0nm.m.pipedream.net with the package name embedded in the URL path (https://eo8f3m3ho26a0nm.m.pipedream.net/vercel/<pkg>). The receiving Pipedream endpoint captures the source IP, hostname context, and confirmation that this squatted name was resolved and installed. The implausibly high 99.99.99 version and the embedded 'Proof by @0xWise' string are consistent with a dependency-confusion payload designed to win version resolution against an internal package of the same name and beacon successful installs on internal build systems to the researcher/attacker's collector. ENTRY server.js (install-hook: node server.js) - Install Hook Executes Local JS File in package.json - Preinstall Script in package.json - Postinstall Script in package.json DESTINATION - 2 exfil (reconstructed, custom-c2) (values recorded in verified_iocs) EXFIL - OAST/Interactsh Exfiltration in server.js: "pipedream.net" - Data Encoding for Exfiltration in server.js: "encodeURIComponent(packages" - Network Request in server.js: "https.get(" OBFUSCATION - recovered 1 urls, 1 domains from decoded/deobfuscated content ADDITIONAL FINDINGS - Suspicious URL Pattern in Template Literal in server.js: "https://eo8f3m3ho26a0nm.m.pipedream.net/vercel/${...}" - Brand New Package PAYLOAD FILES server.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownchat-adapter-matrixall (affected)

References

advisory
vendor

Browse GCVE Records

400 records in the GCVE database · Updated September 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›