VDB

GCVE-110-OSM-2026-12716

GCVE-110-OSM-2026-12716
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published September 30, 2026
package.json declares its only runtime dependency, `node-net-pool`, as an https tarball pointing at the `main` branch of an unrelated GitHub account (`https://github.com/trktgq0wbre1/node-net-pool/archive/refs/heads/main.tar.gz`) — no version pin, no commit SHA, no integrity hash. `npm install` fetches whatever bytes currently live at that mutable URL and executes any lifecycle scripts they contain on the installer's machine. In addition, lib/cache.js runs `module.require('node-net-pool')` inside a swallowed try/catch at top level, so the third-party payload also loads when a consumer `require()`s the package, extending the code-execution surface beyond install time to any downstream import. The account owning the tarball URL is unrelated to the package publisher, so whoever controls that branch controls arbitrary code delivered to every installer. ENTRY index.js (main: index.js) - URL-Based Dependency in package.json: ""dependencies": { "node-net-pool": "https://github.com/trktgq0wbre1/node-net-poo..." - Install Hook Executes Local JS File in [node-net-pool] package.json: ""postinstall": "node index.js"" EXFIL - Data Encoding for Exfiltration in lib/crypto.js: "Buffer.from(data).toString('base64')" - Data Encoding for Exfiltration in lib/http.js: "encodeURIComponent(k) + '=' + encodeURIComponent(v" - Data Encoding for Exfiltration in lib/totp.js: "encodeURIComponent(issuer || '')}:${encodeURIComponent(account)}?${qs" - Network Request in [node-net-pool] index.js: "https.request(" - System Information Collection in [node-net-pool] index.js: "process.platform" OBFUSCATION - Dynamic Base64 Decoding in lib/crypto.js: "Buffer.from(data, 'base64')" - Decoded Base64 Content in index.js - Decoded Base64 Content in lib/crypto.js - Decoded Base64 Content in [deobfuscated] lib/crypto.js - Base64 Encoded Payload in index.js: "'eyJicm93c2VyIjoiQ2hyb21lIiwiYnJvd3Nlcl91c2VyX2FnZW50IjoiQ2hyb21lIiwiY2xpZW50X2J..." - Strings Extracted from Deobfuscated Code in lib/crypto.js - recovered 1 ipv4 from decoded/deobfuscated content ADDITIONAL FINDINGS - Stealth Background Process Spawning in [node-net-pool] index.js: "spawn( "reg.exe", [ "ADD", "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\..." - Very New NPM Publisher Account - Shell Command Execution in [node-net-pool] index.js: "require("child_process")" - Silent Process Execution in [node-net-pool] index.js: "stdio: "ignore"" - Detached Child Process Payload in [node-net-pool] index.js: "spawn( "reg.exe", [ "ADD", "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\..." PAYLOAD FILES [node-net-pool] index.js (+ lib/crypto.js)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownmfahelperall (affected)—

References

advisory
vendor

Browse GCVE Records

3,112 records in the GCVE database · Updated October 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›