VDB

GCVE-110-OSM-2026-12715

GCVE-110-OSM-2026-12715
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published September 30, 2026
The package declares scripts.postinstall = 'node index.js'. On install, index.js performs an HTTPS GET to the hardcoded host fabric-npm.gm-service.xyz at path /p and passes the response body to vm.runInContext, executing whatever code the server returns on the installer's machine. The host and path are stored in short obfuscated variables (_h, _p). The package's stated purpose ('Native asset loader bridge for Fabric mod environments') is contradicted by its shipped contents: lib/renderer.js is an inert stub returning no-op { status: "ok" } shader results and has no relationship to the actual install-time behavior. The mod-utility framing functions as cover for an install-time remote-code loader whose payload is attacker-mutable and unpinned. ENTRY index.js (install-hook: node index.js) - Install Hook Executes Local JS File in package.json DESTINATION - 1 exfil (custom-c2) (values recorded in verified_iocs) EXFIL - Network Request in index.js: "https.get(" ADDITIONAL FINDINGS - Dynamic Code Execution in index.js: "vm.runInContext" - Dangerous Function Calls in index.js: "require("vm")" - Very New NPM Publisher Account PAYLOAD FILES index.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownfabric-mod-utilsall (affected)—

References

advisory
vendor

Browse GCVE Records

3,112 records in the GCVE database · Updated October 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›