VDB
GCVE-110-OSM-2026-12691
GCVE-110-OSM-2026-12691
Advisory PublishedCVSS 5.4/10
package.json declares a preinstall lifecycle hook that runs `wget` to a hardcoded webhook.site collector URL (https://webhook.site/3fcfa5af-1b4e-4556-9d48-26190d02795f/), passing `$(whoami)`, `$(hostname)`, and `$(pwd)` as query parameters. On `npm install`, npm invokes the preinstall script automatically, so the installer's OS username, host name, and current working directory are transmitted to an anonymous third-party webhook collector without any user action. This is the canonical dependency-confusion / reconnaissance beacon shape: an otherwise-empty package whose only on-install effect is to phone home installer identity to an attacker-chosen endpoint, typically used to confirm ingress into a target's internal build environment before staging a follow-on payload.
ENTRY
index.js (main: index.js)
- Preinstall Script in package.json: ""preinstall": "wget --quiet \""
DESTINATION
- 1 exfil (webhookServices)
(values recorded in verified_iocs)
EXFIL
- OAST/Interactsh Exfiltration in package.json: "webhook.site"
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | git-en-boite-logging | all (affected) | — |
Aliases
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.