VDB

GCVE-110-OSM-2026-6657

GCVE-110-OSM-2026-6657
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published June 25, 2026
Malicious package detected. Behaviors: obfuscated code, install-time execution. ENTRY scripts/postinstall.js (install-hook: node scripts/postinstall.js) - Install Hook Executes Local JS File in package.json DESTINATION - deobfuscated: a0bw.aZ (fetched-payload, deobfuscated) - deobfuscated: a0bw.bd (fetched-payload, deobfuscated) - deobfuscated: a0bw.bf (fetched-payload, deobfuscated) - deobfuscated: a0bw.bi (fetched-payload, deobfuscated) - deobfuscated: a0bw.bl (fetched-payload, deobfuscated) - deobfuscated: a0bw.bn (fetched-payload, deobfuscated) - deobfuscated: a0bw.bq (fetched-payload, deobfuscated) - deobfuscated: a0bw.bw (fetched-payload, deobfuscated) (+41 more) OBFUSCATION - IOCs Found in Deobfuscated Code in scripts/postinstall.js - Obfuscation: augmented proxied array function replacements in scripts/postinstall.js - Decoded Hex Escape Content in scripts/postinstall.js (x248) - Hex Encoded Strings in scripts/postinstall.js: "'\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x7..." - Unicode Escape Obfuscation in scripts/postinstall.js: "\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74..." - Obfuscation patterns: hexHeavy in scripts/postinstall.js - recovered 49 domains, 49 _domainCandidates from decoded/deobfuscated content ADDITIONAL FINDINGS - Publisher Has Other Malicious Packages PAYLOAD FILES scripts/postinstall.js INDICATORS (IOCs) - urls: https://docs.colibri-event-types.io/platform/megamarket-ru-web, https://jira.colibri-event-types.io/projects/PLATFORM, https://npm.colibri-event-types.io, https://github.colibri-event-types.io/platform/megamarket-ru-web.git - emails: platform@colibri-event-types.io - payloadFileHash: a92ed55d3e9547129c2ffa100817425fefef5197646283ce0aad42c19b0620bb

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@colibri-event-types/megamarket-ru-weball (affected)

Browse GCVE Records

74,108 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›