VDB

GCVE-110-OSM-2026-12711

GCVE-110-OSM-2026-12711
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published September 30, 2026
package.json declares scripts.postinstall = 'node index.js'. index.js is a 143-byte stub whose only behavior is to dynamically import the sole declared dependency 'originaldevelopmentstelemetry@1.2.2' and invoke its exported downloadAndRunUpdate() function. On every 'npm install', control is handed to that external package, which by name and by its own exported API downloads and runs an 'update' payload on the installer's machine. The shipped bytes are inert; the entire install-time effect lives in an unaudited third-party package whose author controls arbitrary code execution on installers. Package name 'developmentstelemetry' with a self-labeled 'Gets telemetry data' description and author 'originaldevelopment' matches the wrapper-that-only-calls-another-package shape used to funnel installs into a payload-bearing dependency. ENTRY index.js (install-hook: node index.js) - Install Hook Executes Local JS File in package.json

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowndevelopmentstelemetryall (affected)—

References

advisory
vendor

Browse GCVE Records

3,112 records in the GCVE database · Updated October 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›