VDB
GCVE-110-OSM-2026-13256
GCVE-110-OSM-2026-13256
Advisory PublishedCVSS 5.4/10
package.json declares a preinstall script that runs index.js on npm install. index.js collects host identifiers (os.homedir(), os.hostname(), os.userInfo().username, dns.getServers(), current working directory) along with the contents of the package.json and POSTs them over HTTPS to the hardcoded external host meta.brs.cx. This behavior fires automatically on install with no user interaction, and the collected data is characteristic of dependency-confusion / internal-name reconnaissance beacons used to identify targets for follow-on attacks.
ENTRY
index.js (install-hook: node index.js)
- Install Hook Executes Local JS File in package.json
DESTINATION
- 1 exfil (custom-c2)
(values recorded in verified_iocs)
EXFIL
- OAST/Interactsh Exfiltration in index.js: "burpcollaborator.net"
- System Information Exfiltration in index.js: "dns.getServers(), r: packageJSON ? packageJSON.___resolved : undefined, v: packa..."
- Network Request in index.js: "https.request("
- System Information Collection in index.js: "os.userInfo()"
- Suspicious Domain in index.js: "burpcollaborator.net"
ADDITIONAL FINDINGS
- Platform Detection with Data Collection in index.js: "JSON.stringify({ p: package, c: __dirname, hd: os.homedir(), hn: os.hostname(), ..."
- Brand New Package
PAYLOAD FILES
index.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | com.epi.e2e_test | all (affected) | — |
Aliases
Browse GCVE Records
3,130 records in the GCVE database · Updated October 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.