VDB
GCVE-110-OSM-2026-13306
GCVE-110-OSM-2026-13306
Advisory PublishedCVSS 5.4/10
package.json declares a single dependency 'ltidisafe' sourced directly from the off-registry URL https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.8.2.tgz, with no registry version range and no integrity hash. On npm install, npm fetches and installs whatever bytes that URL currently serves, executing any lifecycle scripts contained inside the fetched tarball under the installer's account. The GCS bucket host is not tied to any declared publisher of this package, and the fetched content can be changed at any time without a corresponding package republish. The shipped index.js is an empty stub, so the manifest's off-registry fetch is the package's entire effect on the installer. The package name 'unified-platform' at the implausibly high version 99.9.1 is consistent with a dependency-confusion lure targeting an internal name.
ENTRY
index.js (main: index.js)
- URL-Based Dependency in package.json: ""dependencies": { "ltidisafe": "https://ltidi.storage.googleapis.com/depenconf/l..."
- Install Hook Executes Local JS File in [ltidisafe] package.json: ""preinstall": "node test.js > /dev/null 2>&1""
EXFIL
- OAST/Interactsh Exfiltration in [ltidisafe] test.js: "oastify.com"
- Network Request in [ltidisafe] index.js: "http.request("
- System Information Collection in [ltidisafe] test.js: "os.userInfo()"
- Suspicious Domain in [ltidisafe] test.js: "oastify.com"
OBFUSCATION
- recovered 1 domains from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Very New NPM Publisher Account
- Publisher Has Other Malicious Packages
- Rapid Version Publishing
PAYLOAD FILES
[ltidisafe] test.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | unified-platform | all (affected) | — |
Aliases
Browse GCVE Records
3,130 records in the GCVE database · Updated October 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.