VDB
GCVE-110-OSM-2026-13395
GCVE-110-OSM-2026-13395
Advisory PublishedCVSS 8.8/10
The package ships a postinstall script (`scripts.postinstall` runs `node beacon.cjs`) and a top-level `require('./beacon.cjs').fire()` in `index.js` that POST installer host metadata — hostname, install path, cwd, Node version, and package name — to the hardcoded plain-HTTP bare-IP endpoint `http://185.158.107.175:8787/_ah/dc`. The exfiltration fires automatically both on `npm install` and on any `require()` of the package. `index.js` otherwise exports a Proxy returning no-op functions for any property access, so the package has no legitimate functionality; its sole effect is the callback to the hardcoded endpoint. The destination is not associated with any publisher domain and is unrelated to the self-described 'compatibility shim' purpose. The shape (stub Proxy export + install/require-time beacon to a bare-IP collector) is a dependency-confusion / typosquat proof-of-installation beacon.
ADDITIONAL FINDINGS
- Brand New Package
- Very New NPM Publisher Account
- Publisher Shows Burner-Account Pattern
- Rapid Version Publishing
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @wxwxtest/testrrrdd | 0.0.0-stage (affected) | — |
Aliases
Browse GCVE Records
3,328 records in the GCVE database · Updated October 10, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.