VDB

GCVE-110-OSM-2026-13256

GCVE-110-OSM-2026-13256
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published September 30, 2026
package.json declares a preinstall script that runs index.js on npm install. index.js collects host identifiers (os.homedir(), os.hostname(), os.userInfo().username, dns.getServers(), current working directory) along with the contents of the package.json and POSTs them over HTTPS to the hardcoded external host meta.brs.cx. This behavior fires automatically on install with no user interaction, and the collected data is characteristic of dependency-confusion / internal-name reconnaissance beacons used to identify targets for follow-on attacks. ENTRY index.js (install-hook: node index.js) - Install Hook Executes Local JS File in package.json DESTINATION - 1 exfil (custom-c2) (values recorded in verified_iocs) EXFIL - OAST/Interactsh Exfiltration in index.js: "burpcollaborator.net" - System Information Exfiltration in index.js: "dns.getServers(), r: packageJSON ? packageJSON.___resolved : undefined, v: packa..." - Network Request in index.js: "https.request(" - System Information Collection in index.js: "os.userInfo()" - Suspicious Domain in index.js: "burpcollaborator.net" ADDITIONAL FINDINGS - Platform Detection with Data Collection in index.js: "JSON.stringify({ p: package, c: __dirname, hd: os.homedir(), hn: os.hostname(), ..." - Brand New Package PAYLOAD FILES index.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknowncom.epi.e2e_testall (affected)—

References

advisory
vendor

Browse GCVE Records

3,130 records in the GCVE database · Updated October 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›