VDB
GCVE-110-OSM-2026-13413
GCVE-110-OSM-2026-13413
Advisory PublishedCVSS 8.8/10
On npm install, the package's preinstall hook executes install.js, which collects host identifiers (os.hostname(), process.cwd(), username) and reads flag files from /flag, /flag.txt, /app/flag, /home/node/flag, and /tmp/flag, then PUTs the collected data to the hardcoded bare-IP endpoint http://154.57.164.66:39270/api/modules/* over plain HTTP. install.js is additionally wrapped as a PowerShell here-string (opening with @" and closing with "@ | Out-File -Encoding ascii install.js), structured as a polyglot that can rewrite itself on Windows before Node executes the exfiltration payload. The behavior fires automatically on default install and has no relationship to the package's stated color-utility purpose.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @praveenvjpm/color-utils-7210 | all (affected) | — |
Browse GCVE Records
3,328 records in the GCVE database · Updated October 10, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.