VDB
GCVE-110-OSM-2026-13401
GCVE-110-OSM-2026-13401
Advisory PublishedCVSS 5.4/10
On npm install, the package's preinstall hook executes beacon.js, which performs a DNS lookup and HTTPS GET to a hardcoded interactsh (OAST) subdomain under oast.site, embedding the package name in the path. The implausibly high version number (99.0.0) combined with the generic scope-plus-name is the canonical shape of a dependency-confusion probe: publish a public package reusing an internal name at a version high enough to win resolution, and record every host that resolves it. Each install leaks the installer's egress IP and the fact that an internal-named package was pulled from the public registry to a third-party-controlled collector, confirming to the operator that the target organization is exploitable for a follow-on malicious release under the same name. No installer secrets, environment variables, or filesystem contents are read, and no remote code is executed from the response, but the beacon itself materializes attacker benefit (reconnaissance of vulnerable internal names) at install time.
ENTRY
beacon.js (install-hook: node beacon.js)
- Install Hook Executes Local JS File in package.json
DESTINATION
- 1 exfil (custom-c2)
(values recorded in verified_iocs)
EXFIL
- OAST/Interactsh Exfiltration in beacon.js: "oast.site"
ADDITIONAL FINDINGS
- Publisher Has Other Malicious Packages
PAYLOAD FILES
beacon.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @dransay/db | all (affected) | — |
Aliases
Browse GCVE Records
3,328 records in the GCVE database · Updated October 10, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.