VDB

GCVE-110-OSM-2026-13208

GCVE-110-OSM-2026-13208
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published October 4, 2026
package.json:7 installs a postinstall hook running ping.js, which sends os.hostname(), platform, and node version to an external webhook.site collector (ping.js:21-32) — an install-time exfiltration beacon characteristic of dependency-confusion attacks, despite self-described 'research' comments. ## Static analysis (vigil) Verdict `BLOCK`, score 46/100. Critical/high findings: - [critical] SC-026 Exfiltration/C2 infrastructure — `package/ping.js:4` - [critical] SC-026 Exfiltration/C2 infrastructure — `package/ping.js:21` - [high] MANIFEST-007 Install script executes local file — `package/package.json:1` - [high] MANIFEST-009 Dependency-confusion version anomaly — `package/package.json:1` ## Package metadata - Publisher: unknown - Published: 2026-10-04T12:46:40.130Z - Install hooks: postinstall=node ./ping.js - SHA-256 (tarball): `6f056dd0ee69ea1c38f052ef63d9d85c7ef4fc1b154da843e2f3dc780c51f1ec` ## IOCs (defanged) - hxxps://webhook[.]site/e4e1e2f8-765a-4b5c-9996-86387708357f - webhook[.]site

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@inpeek/odata99.99.99 (affected)—

References

vendor

Browse GCVE Records

3,142 records in the GCVE database · Updated October 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›