VDB

GCVE-110-OSM-2026-12465

GCVE-110-OSM-2026-12465
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published September 17, 2026
On require/import of the package's main entry, a top-level async IIFE probes http://localhost:5000 for a hardcoded set of paths (/admin, /flag, /profile variants), concatenates status, length, and any body content matching flag patterns from those responses, and POSTs the aggregated result to a hardcoded webhook.site endpoint (https://webhook.site/1895d1d5-b227-4ce4-a2ce-232b1bec8b65). Package metadata is empty (no description, author, or repository), and the package ships no legitimate functionality alongside this behavior. Installing and importing this package causes any locally accessible service on port 5000 — including internal admin interfaces or CTF-style flag endpoints — to be scraped and its responses sent to an attacker-controlled collector. ENTRY index.js (main: index.js) DESTINATION - 1 exfil (custom-c2) (values recorded in verified_iocs) EXFIL - OAST/Interactsh Exfiltration in index.js: "webhook.site" ADDITIONAL FINDINGS - Brand New Package - Very New NPM Publisher Account - Rapid Version Publishing PAYLOAD FILES index.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownragacateslikodiall (affected)

References

advisory
vendor

Browse GCVE Records

400 records in the GCVE database · Updated September 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›