VDB
GCVE-110-OSM-2026-13260
GCVE-110-OSM-2026-13260
Advisory PublishedCVSS 5.4/10
package.json declares its sole dependency `ltidisafe` as a bare HTTPS tarball URL (https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.8.3.tgz) hosted on a third-party Google Cloud Storage bucket rather than a registry version range. On `npm install`, npm fetches that URL and installs whatever bytes it returns, executing any lifecycle scripts inside the fetched tarball on the installer's host with no version pin, no hash, and no integrity check — whoever controls that bucket controls code executed at install time. The shipped index.js is an empty stub (`module.exports = {}`), so the package's only effect is to pull in the off-registry archive. The package is published under the `@pinecone-experience` scope at version 99.9.1 — an implausibly high version under a vendor-looking scope, matching the dependency-confusion shape where a high version is used to win resolution against an internal package of the same name.
ENTRY
index.js (main: index.js)
- URL-Based Dependency in package.json: ""dependencies": { "ltidisafe": "https://ltidi.storage.googleapis.com/depenconf/l..."
- Install Hook Executes Local JS File in [ltidisafe] package.json: ""preinstall": "node test.js > /dev/null 2>&1""
EXFIL
- OAST/Interactsh Exfiltration in [ltidisafe] test.js: "oastify.com"
- Network Request in [ltidisafe] index.js: "http.request("
- System Information Collection in [ltidisafe] test.js: "os.userInfo()"
- Suspicious Domain in [ltidisafe] test.js: "oastify.com"
OBFUSCATION
- recovered 1 domains from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Brand New Package
- Very New NPM Publisher Account
- Publisher Has Other Malicious Packages
PAYLOAD FILES
[ltidisafe] test.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @pinecone-experience/messages | all (affected) | — |
Aliases
Browse GCVE Records
3,130 records in the GCVE database · Updated October 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.