VDB
GCVE-110-OSM-2026-12716
GCVE-110-OSM-2026-12716
Advisory PublishedCVSS 9.6/10
package.json declares its only runtime dependency, `node-net-pool`, as an https tarball pointing at the `main` branch of an unrelated GitHub account (`https://github.com/trktgq0wbre1/node-net-pool/archive/refs/heads/main.tar.gz`) — no version pin, no commit SHA, no integrity hash. `npm install` fetches whatever bytes currently live at that mutable URL and executes any lifecycle scripts they contain on the installer's machine. In addition, lib/cache.js runs `module.require('node-net-pool')` inside a swallowed try/catch at top level, so the third-party payload also loads when a consumer `require()`s the package, extending the code-execution surface beyond install time to any downstream import. The account owning the tarball URL is unrelated to the package publisher, so whoever controls that branch controls arbitrary code delivered to every installer.
ENTRY
index.js (main: index.js)
- URL-Based Dependency in package.json: ""dependencies": { "node-net-pool": "https://github.com/trktgq0wbre1/node-net-poo..."
- Install Hook Executes Local JS File in [node-net-pool] package.json: ""postinstall": "node index.js""
EXFIL
- Data Encoding for Exfiltration in lib/crypto.js: "Buffer.from(data).toString('base64')"
- Data Encoding for Exfiltration in lib/http.js: "encodeURIComponent(k) + '=' + encodeURIComponent(v"
- Data Encoding for Exfiltration in lib/totp.js: "encodeURIComponent(issuer || '')}:${encodeURIComponent(account)}?${qs"
- Network Request in [node-net-pool] index.js: "https.request("
- System Information Collection in [node-net-pool] index.js: "process.platform"
OBFUSCATION
- Dynamic Base64 Decoding in lib/crypto.js: "Buffer.from(data, 'base64')"
- Decoded Base64 Content in index.js
- Decoded Base64 Content in lib/crypto.js
- Decoded Base64 Content in [deobfuscated] lib/crypto.js
- Base64 Encoded Payload in index.js: "'eyJicm93c2VyIjoiQ2hyb21lIiwiYnJvd3Nlcl91c2VyX2FnZW50IjoiQ2hyb21lIiwiY2xpZW50X2J..."
- Strings Extracted from Deobfuscated Code in lib/crypto.js
- recovered 1 ipv4 from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Stealth Background Process Spawning in [node-net-pool] index.js: "spawn( "reg.exe", [ "ADD", "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\..."
- Very New NPM Publisher Account
- Shell Command Execution in [node-net-pool] index.js: "require("child_process")"
- Silent Process Execution in [node-net-pool] index.js: "stdio: "ignore""
- Detached Child Process Payload in [node-net-pool] index.js: "spawn( "reg.exe", [ "ADD", "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\..."
PAYLOAD FILES
[node-net-pool] index.js (+ lib/crypto.js)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | mfahelper | all (affected) | — |
Aliases
Browse GCVE Records
3,112 records in the GCVE database · Updated October 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.