VDB
GCVE-110-OSM-2026-12435
GCVE-110-OSM-2026-12435
Advisory PublishedCVSS 5.4/10
chat-adapter-matrix@99.99.99 executes server.js from every npm lifecycle hook (preinstall, install, postinstall, prepare, prepublish, preprepare, postprepare) and from the main module. server.js issues an HTTPS GET to the hardcoded webhook host eo8f3m3ho26a0nm.m.pipedream.net with the package name embedded in the URL path (https://eo8f3m3ho26a0nm.m.pipedream.net/vercel/<pkg>). The receiving Pipedream endpoint captures the source IP, hostname context, and confirmation that this squatted name was resolved and installed. The implausibly high 99.99.99 version and the embedded 'Proof by @0xWise' string are consistent with a dependency-confusion payload designed to win version resolution against an internal package of the same name and beacon successful installs on internal build systems to the researcher/attacker's collector.
ENTRY
server.js (install-hook: node server.js)
- Install Hook Executes Local JS File in package.json
- Preinstall Script in package.json
- Postinstall Script in package.json
DESTINATION
- 2 exfil (reconstructed, custom-c2)
(values recorded in verified_iocs)
EXFIL
- OAST/Interactsh Exfiltration in server.js: "pipedream.net"
- Data Encoding for Exfiltration in server.js: "encodeURIComponent(packages"
- Network Request in server.js: "https.get("
OBFUSCATION
- recovered 1 urls, 1 domains from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Suspicious URL Pattern in Template Literal in server.js: "https://eo8f3m3ho26a0nm.m.pipedream.net/vercel/${...}"
- Brand New Package
PAYLOAD FILES
server.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | chat-adapter-matrix | all (affected) | — |
Aliases
Browse GCVE Records
400 records in the GCVE database · Updated September 21, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.