VDB

GCVE-110-OSM-2026-12439

GCVE-110-OSM-2026-12439
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published September 21, 2026
The package declares both preinstall and postinstall lifecycle hooks that execute index.js, which issues a plaintext HTTP GET to the hardcoded bare IP 128.199.122.145 with the package name in the query string. The beacon fires unconditionally on npm install, confirming to the operator of that host that the package was resolved and installed on the target machine. The package has no other functionality: an empty description, an inflated version (99.99.99), and a manifest that declares a lookalike dependency `requests` alongside a duplicate capitalized `Dependencies` key referencing `request` — the shape of a dependency-confusion probe rather than a functional library. ENTRY index.js (install-hook: node index.js --save-prod) - Install Hook Executes Local JS File in package.json - Preinstall Script in package.json DESTINATION - 2 exfil (reconstructed, custom-c2) (values recorded in verified_iocs) EXFIL - Network Request in index.js: "request(`http:" OBFUSCATION - recovered 1 urls, 1 domains from decoded/deobfuscated content ADDITIONAL FINDINGS - Reconstructed Obfuscated URL in index.js: "http://128.199.122.145/?test1gg234" PAYLOAD FILES index.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowntest1gg234all (affected)

References

advisory
vendor

Browse GCVE Records

400 records in the GCVE database · Updated September 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›