VDB
GCVE-110-OSM-2026-13398
GCVE-110-OSM-2026-13398
Advisory PublishedCVSS 8.8/10
wie888r@3.0.0 ships a stub main (index.js) that exports a Proxy returning no-op functions for any property access, so bundlers that resolve this name do not crash. The package's postinstall script runs beacon.cjs, which collects host identifiers (hostname, install path, cwd, node version) and POSTs them to the hardcoded bare-IP endpoint http://185.158.107.175:8787/_ah/dc over plain HTTP. index.js invokes the same beacon on require, so the exfiltration fires both at install time and whenever the module is loaded. The destination is not a documented first-party service, and the package's self-described 'compatibility shim' purpose is contradicted by the beacon behavior. The combination of a no-op Proxy stub, a hardcoded non-publisher bare-IP endpoint, and dual install-time plus import-time reconnaissance is the standard shape of a dependency-confusion / typosquat probe used to confirm resolution of an unexpected name inside a target environment.
ENTRY
beacon.cjs (install-hook: node beacon.cjs)
- Install Hook Executes Local JS File in package.json
DESTINATION
- 2 exfil (custom-c2)
(values recorded in verified_iocs)
EXFIL
- Network Request in beacon.cjs: "request({ hostname: u.hostname, port: u.port || (u.protocol === 'https:"
- Suspicious Domain in beacon.cjs: "http://185.158.107.175"
ADDITIONAL FINDINGS
- Brand New Package
- Very New NPM Publisher Account
- Publisher Shows Burner-Account Pattern
- Rapid Version Publishing
PAYLOAD FILES
beacon.cjs
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | wie888r | all (affected) | — |
Aliases
Browse GCVE Records
3,328 records in the GCVE database · Updated October 10, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.