VDB

GCVE-110-OSM-2026-3328

GCVE-110-OSM-2026-3328
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published April 29, 2026
Bug bounty dependency confusion attempt. Package exfiltrates basic system information (hostname, IP, DNS) to security research infrastructure. Behaviors: data exfiltration, install-time execution. Payload: ms_audit.sh Key findings: - OAST/Interactsh Exfiltration in ms_audit.sh: "webhook.site" - Publisher Has Other Malicious Packages - Brand New Package - Very New NPM Publisher Account IOCs: - urls: https://webhook.site/bebcbad8-da0e-43e1-af8d-9d069ca3bd42, http://169.254.169.254/latest/meta-data/product-name - webhookServices: https://webhook.site/bebcbad8-da0e-43e1-af8d-9d069ca3bd42 - payloadFileHash: d547411e9500301f4cf01609753885387b6886e13401e51863a74ca93c554c7f

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownaliyun-internal-configall (affected)

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›