VDB
GCVE-110-OSM-2026-12439
GCVE-110-OSM-2026-12439
Advisory PublishedCVSS 9.6/10
The package declares both preinstall and postinstall lifecycle hooks that execute index.js, which issues a plaintext HTTP GET to the hardcoded bare IP 128.199.122.145 with the package name in the query string. The beacon fires unconditionally on npm install, confirming to the operator of that host that the package was resolved and installed on the target machine. The package has no other functionality: an empty description, an inflated version (99.99.99), and a manifest that declares a lookalike dependency `requests` alongside a duplicate capitalized `Dependencies` key referencing `request` — the shape of a dependency-confusion probe rather than a functional library.
ENTRY
index.js (install-hook: node index.js --save-prod)
- Install Hook Executes Local JS File in package.json
- Preinstall Script in package.json
DESTINATION
- 2 exfil (reconstructed, custom-c2)
(values recorded in verified_iocs)
EXFIL
- Network Request in index.js: "request(`http:"
OBFUSCATION
- recovered 1 urls, 1 domains from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Reconstructed Obfuscated URL in index.js: "http://128.199.122.145/?test1gg234"
PAYLOAD FILES
index.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | test1gg234 | all (affected) | — |
Aliases
Browse GCVE Records
400 records in the GCVE database · Updated September 21, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.