VDB
GCVE-110-OSM-2026-12711
GCVE-110-OSM-2026-12711
Advisory PublishedCVSS 8.8/10
package.json declares scripts.postinstall = 'node index.js'. index.js is a 143-byte stub whose only behavior is to dynamically import the sole declared dependency 'originaldevelopmentstelemetry@1.2.2' and invoke its exported downloadAndRunUpdate() function. On every 'npm install', control is handed to that external package, which by name and by its own exported API downloads and runs an 'update' payload on the installer's machine. The shipped bytes are inert; the entire install-time effect lives in an unaudited third-party package whose author controls arbitrary code execution on installers. Package name 'developmentstelemetry' with a self-labeled 'Gets telemetry data' description and author 'originaldevelopment' matches the wrapper-that-only-calls-another-package shape used to funnel installs into a payload-bearing dependency.
ENTRY
index.js (install-hook: node index.js)
- Install Hook Executes Local JS File in package.json
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | developmentstelemetry | all (affected) | — |
Aliases
Browse GCVE Records
3,112 records in the GCVE database · Updated October 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.