VDB
GCVE-110-OSM-2026-13209
GCVE-110-OSM-2026-13209
Advisory PublishedCVSS 5.4/10
This package self-identifies as a Bug Bounty Switzerland dependency-confusion PoC targeting Energie Wasser Bern (EWB), published by drdoctor@wearehackerone.com. The behavior is consistent with that claim: ping.js fires a single HTTPS GET to an OAST endpoint encoding only hostname, platform, and Node version — no env vars, no credential theft, no filesystem reads, no shell execution. The version number (99.99.x) and scope (@inpeek/*) are classic dependency-confusion probe indicators, and the internal registry target (registry.it.ewb.ch) is named explicitly in comments. While the technical behavior (OAST beacon on postinstall) is indistinguishable from real malware at the code level, the totality of metadata — HackerOne email, bugbounty.ch repository, explicit researcher commentary, no obfuscation, no destructive payload — is consistent with a legitimate authorized security test, not a threat actor.
## Static analysis (vigil)
Verdict `BLOCK`, score 46/100. Critical/high findings:
- [critical] SC-026 Exfiltration/C2 infrastructure — `package/ping.js:4`
- [critical] SC-026 Exfiltration/C2 infrastructure — `package/ping.js:21`
- [high] MANIFEST-007 Install script executes local file — `package/package.json:1`
- [high] MANIFEST-009 Dependency-confusion version anomaly — `package/package.json:1`
## Package metadata
- Publisher: unknown
- Published: 2026-10-04T12:46:42.611Z
- Install hooks: postinstall=node ./ping.js
- SHA-256 (tarball): `485850757bc1aefc7409a132efb0c67e062ef868dd93fc8a34ab497fd1e7e875`
## IOCs (defanged)
- hxxps://webhook[.]site/e4e1e2f8-765a-4b5c-9996-86387708357f
- webhook[.]site
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @inpeek/odata-angular | all (affected) | — |
Browse GCVE Records
3,142 records in the GCVE database · Updated October 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.