VDB

GCVE-110-OSM-2026-1444

GCVE-110-OSM-2026-1444
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published April 5, 2026
Suspected dependency confusion attack. Behaviors: data exfiltration, network activity, install-time execution. Payload: postinstall.js Key findings: - Environment Variable Exfiltration in postinstall.js: "process.env.GITHUB_ACTIONS || "false", repo: process.env.GITHUB_REPOSITORY || ..." - System Information Exfiltration in postinstall.js: "os.platform(), arch: os.arch(), ci: process.env.CI || "false", gh: process..." - OAST/Interactsh Exfiltration in postinstall.js: "oastify.com" - HTTP Data Exfiltration in postinstall.js: "os.hostname(), user: os.userInfo().username, cwd: process.cwd(), }); const ..." - Suspicious Domain in postinstall.js: "oastify.com" IOCs: - domains: process.env.CI, vts548y2xqoa4m3308e8d4kqqhw8k18q.oastify.com - payloadFileHash: 4ece814978bbc9dddbefa1cb1e0464abd623e21f25bea0eec9c522ea84606525

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownpt-sc-loggerall (affected)

References

vendor

Browse GCVE Records

74,267 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›