VDB

GCVE-110-OSM-2026-13209

GCVE-110-OSM-2026-13209
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published October 4, 2026
This package self-identifies as a Bug Bounty Switzerland dependency-confusion PoC targeting Energie Wasser Bern (EWB), published by drdoctor@wearehackerone.com. The behavior is consistent with that claim: ping.js fires a single HTTPS GET to an OAST endpoint encoding only hostname, platform, and Node version — no env vars, no credential theft, no filesystem reads, no shell execution. The version number (99.99.x) and scope (@inpeek/*) are classic dependency-confusion probe indicators, and the internal registry target (registry.it.ewb.ch) is named explicitly in comments. While the technical behavior (OAST beacon on postinstall) is indistinguishable from real malware at the code level, the totality of metadata — HackerOne email, bugbounty.ch repository, explicit researcher commentary, no obfuscation, no destructive payload — is consistent with a legitimate authorized security test, not a threat actor. ## Static analysis (vigil) Verdict `BLOCK`, score 46/100. Critical/high findings: - [critical] SC-026 Exfiltration/C2 infrastructure — `package/ping.js:4` - [critical] SC-026 Exfiltration/C2 infrastructure — `package/ping.js:21` - [high] MANIFEST-007 Install script executes local file — `package/package.json:1` - [high] MANIFEST-009 Dependency-confusion version anomaly — `package/package.json:1` ## Package metadata - Publisher: unknown - Published: 2026-10-04T12:46:42.611Z - Install hooks: postinstall=node ./ping.js - SHA-256 (tarball): `485850757bc1aefc7409a132efb0c67e062ef868dd93fc8a34ab497fd1e7e875` ## IOCs (defanged) - hxxps://webhook[.]site/e4e1e2f8-765a-4b5c-9996-86387708357f - webhook[.]site

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknown@inpeek/odata-angularall (affected)—

Browse GCVE Records

3,142 records in the GCVE database · Updated October 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›