VDB

GCVE-110-OSM-2026-13401

GCVE-110-OSM-2026-13401
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published October 8, 2026
On npm install, the package's preinstall hook executes beacon.js, which performs a DNS lookup and HTTPS GET to a hardcoded interactsh (OAST) subdomain under oast.site, embedding the package name in the path. The implausibly high version number (99.0.0) combined with the generic scope-plus-name is the canonical shape of a dependency-confusion probe: publish a public package reusing an internal name at a version high enough to win resolution, and record every host that resolves it. Each install leaks the installer's egress IP and the fact that an internal-named package was pulled from the public registry to a third-party-controlled collector, confirming to the operator that the target organization is exploitable for a follow-on malicious release under the same name. No installer secrets, environment variables, or filesystem contents are read, and no remote code is executed from the response, but the beacon itself materializes attacker benefit (reconnaissance of vulnerable internal names) at install time. ENTRY beacon.js (install-hook: node beacon.js) - Install Hook Executes Local JS File in package.json DESTINATION - 1 exfil (custom-c2) (values recorded in verified_iocs) EXFIL - OAST/Interactsh Exfiltration in beacon.js: "oast.site" ADDITIONAL FINDINGS - Publisher Has Other Malicious Packages PAYLOAD FILES beacon.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknown@dransay/dball (affected)—

References

advisory
vendor

Browse GCVE Records

3,328 records in the GCVE database · Updated October 10, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›