VDB

GCVE-110-OSM-2026-13398

GCVE-110-OSM-2026-13398
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published October 8, 2026
wie888r@3.0.0 ships a stub main (index.js) that exports a Proxy returning no-op functions for any property access, so bundlers that resolve this name do not crash. The package's postinstall script runs beacon.cjs, which collects host identifiers (hostname, install path, cwd, node version) and POSTs them to the hardcoded bare-IP endpoint http://185.158.107.175:8787/_ah/dc over plain HTTP. index.js invokes the same beacon on require, so the exfiltration fires both at install time and whenever the module is loaded. The destination is not a documented first-party service, and the package's self-described 'compatibility shim' purpose is contradicted by the beacon behavior. The combination of a no-op Proxy stub, a hardcoded non-publisher bare-IP endpoint, and dual install-time plus import-time reconnaissance is the standard shape of a dependency-confusion / typosquat probe used to confirm resolution of an unexpected name inside a target environment. ENTRY beacon.cjs (install-hook: node beacon.cjs) - Install Hook Executes Local JS File in package.json DESTINATION - 2 exfil (custom-c2) (values recorded in verified_iocs) EXFIL - Network Request in beacon.cjs: "request({ hostname: u.hostname, port: u.port || (u.protocol === 'https:" - Suspicious Domain in beacon.cjs: "http://185.158.107.175" ADDITIONAL FINDINGS - Brand New Package - Very New NPM Publisher Account - Publisher Shows Burner-Account Pattern - Rapid Version Publishing PAYLOAD FILES beacon.cjs

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownwie888rall (affected)—

References

advisory
vendor

Browse GCVE Records

3,328 records in the GCVE database · Updated October 10, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›