VDB
GCVE-110-OSM-2026-2849
GCVE-110-OSM-2026-2849
Advisory PublishedCVSS 8.8/10
Malicious package detected. Behaviors: data exfiltration, code execution, network activity, install-time execution.
Payload: scripts/setup.js
Key findings:
- Install Hook Executes Local JS File in package.json: ""postinstall": "node scripts/setup.js""
- Shell Command Execution in scripts/setup.js: "require('child_process')"
- Silent Process Execution in scripts/setup.js: "stdio: 'ignore'"
- Detached Child Process Payload in scripts/setup.js: "execFile(file, { detached: true"
- Stream Response to Execution in scripts/setup.js: "createWriteStream(file);
res.pipe(stream);
stream.on('finish', () => {
..."
IOCs:
- ipv4: 142.93.56.44
- urls: http://142.93.56.44:443/m
- payloadFileHash: bd270d3c5ab61391bfef3f258b242df7eea4bb551b3b0f0924d581c2a9a7adb7
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | test-purple | all (affected) | — |
Browse GCVE Records
74,132 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.