VDB
GCVE-110-OSM-2026-6657
GCVE-110-OSM-2026-6657
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: obfuscated code, install-time execution.
ENTRY
scripts/postinstall.js (install-hook: node scripts/postinstall.js)
- Install Hook Executes Local JS File in package.json
DESTINATION
- deobfuscated: a0bw.aZ (fetched-payload, deobfuscated)
- deobfuscated: a0bw.bd (fetched-payload, deobfuscated)
- deobfuscated: a0bw.bf (fetched-payload, deobfuscated)
- deobfuscated: a0bw.bi (fetched-payload, deobfuscated)
- deobfuscated: a0bw.bl (fetched-payload, deobfuscated)
- deobfuscated: a0bw.bn (fetched-payload, deobfuscated)
- deobfuscated: a0bw.bq (fetched-payload, deobfuscated)
- deobfuscated: a0bw.bw (fetched-payload, deobfuscated)
(+41 more)
OBFUSCATION
- IOCs Found in Deobfuscated Code in scripts/postinstall.js
- Obfuscation: augmented proxied array function replacements in scripts/postinstall.js
- Decoded Hex Escape Content in scripts/postinstall.js (x248)
- Hex Encoded Strings in scripts/postinstall.js: "'\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x7..."
- Unicode Escape Obfuscation in scripts/postinstall.js: "\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74..."
- Obfuscation patterns: hexHeavy in scripts/postinstall.js
- recovered 49 domains, 49 _domainCandidates from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Publisher Has Other Malicious Packages
PAYLOAD FILES
scripts/postinstall.js
INDICATORS (IOCs)
- urls: https://docs.colibri-event-types.io/platform/megamarket-ru-web, https://jira.colibri-event-types.io/projects/PLATFORM, https://npm.colibri-event-types.io, https://github.colibri-event-types.io/platform/megamarket-ru-web.git
- emails: platform@colibri-event-types.io
- payloadFileHash: a92ed55d3e9547129c2ffa100817425fefef5197646283ce0aad42c19b0620bb
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @colibri-event-types/megamarket-ru-web | all (affected) | — |
Aliases
Browse GCVE Records
74,108 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.