VDB

GCVE-110-OSM-2026-13395

GCVE-110-OSM-2026-13395
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published October 8, 2026
The package ships a postinstall script (`scripts.postinstall` runs `node beacon.cjs`) and a top-level `require('./beacon.cjs').fire()` in `index.js` that POST installer host metadata — hostname, install path, cwd, Node version, and package name — to the hardcoded plain-HTTP bare-IP endpoint `http://185.158.107.175:8787/_ah/dc`. The exfiltration fires automatically both on `npm install` and on any `require()` of the package. `index.js` otherwise exports a Proxy returning no-op functions for any property access, so the package has no legitimate functionality; its sole effect is the callback to the hardcoded endpoint. The destination is not associated with any publisher domain and is unrelated to the self-described 'compatibility shim' purpose. The shape (stub Proxy export + install/require-time beacon to a bare-IP collector) is a dependency-confusion / typosquat proof-of-installation beacon. ADDITIONAL FINDINGS - Brand New Package - Very New NPM Publisher Account - Publisher Shows Burner-Account Pattern - Rapid Version Publishing

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@wxwxtest/testrrrdd0.0.0-stage (affected)—

References

advisory
vendor

Browse GCVE Records

3,328 records in the GCVE database · Updated October 10, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›