VDB
GCVE-110-OSM-2026-13208
GCVE-110-OSM-2026-13208
Advisory PublishedCVSS 8.8/10
package.json:7 installs a postinstall hook running ping.js, which sends os.hostname(), platform, and node version to an external webhook.site collector (ping.js:21-32) — an install-time exfiltration beacon characteristic of dependency-confusion attacks, despite self-described 'research' comments.
## Static analysis (vigil)
Verdict `BLOCK`, score 46/100. Critical/high findings:
- [critical] SC-026 Exfiltration/C2 infrastructure — `package/ping.js:4`
- [critical] SC-026 Exfiltration/C2 infrastructure — `package/ping.js:21`
- [high] MANIFEST-007 Install script executes local file — `package/package.json:1`
- [high] MANIFEST-009 Dependency-confusion version anomaly — `package/package.json:1`
## Package metadata
- Publisher: unknown
- Published: 2026-10-04T12:46:40.130Z
- Install hooks: postinstall=node ./ping.js
- SHA-256 (tarball): `6f056dd0ee69ea1c38f052ef63d9d85c7ef4fc1b154da843e2f3dc780c51f1ec`
## IOCs (defanged)
- hxxps://webhook[.]site/e4e1e2f8-765a-4b5c-9996-86387708357f
- webhook[.]site
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @inpeek/odata | 99.99.99 (affected) | — |
Browse GCVE Records
3,142 records in the GCVE database · Updated October 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.