VDB

GCVE-110-OSM-2026-12714

GCVE-110-OSM-2026-12714
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published September 30, 2026
The package's postinstall hook runs index.js, which performs an HTTPS GET to the hardcoded host https://fabric-npm.gm-service.xyz/p and passes the response body directly to vm.runInContext with a context exposing require, process, Buffer, timers, and console. Whatever bytes that server returns execute at npm install time with full Node privileges on the installer's machine. The advertised purpose ("Native asset loader bridge for Fabric mod environments") does not match the code: lib/renderer.js is an inert stub with no-op exports, and index.js contains only the remote fetch-and-eval loader. The package name evokes the unrelated Fabric Minecraft mod ecosystem, which is a cover story. The remote host controls the payload and can change it at any time, so installer impact is unbounded and can include credential theft, persistence, or lateral movement. ENTRY index.js (install-hook: node index.js) - Install Hook Executes Local JS File in package.json DESTINATION - 1 exfil (custom-c2) (values recorded in verified_iocs) EXFIL - Network Request in index.js: "https.get(" ADDITIONAL FINDINGS - Dynamic Code Execution in index.js: "vm.runInContext" - Dangerous Function Calls in index.js: "require("vm")" - Brand New Package - Very New NPM Publisher Account PAYLOAD FILES index.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownfabric-loader-coreall (affected)—

References

advisory
vendor

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›