VDB

GCVE-110-OSM-2026-8311

GCVE-110-OSM-2026-8311
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published July 18, 2026
Malicious code in fmt-date-lite (npm) Details: --- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (1c8dad7bd90f4cb0dbb1d4ce933bc39f04aefe4940a53605e5c3f30c48a313e4) On `npm install`, the package's postinstall lifecycle script runs the `id` command and transmits the resulting user/group identity to a hardcoded bare-IP endpoint at http://155.190.124.243:6788/ over plain HTTP. Three fallback delivery mechanisms are used (node http.get, curl, wget) to maximize the chance of successful exfiltration across environments. This behavior has no legitimate connection to the package's advertised purpose (a date-formatting utility), and the benign-sounding name and `date-fns-lite` authorship function as cover for the install-time beacon — consistent with a lure/typosquat targeting the date-fns ecosystem. The `id` output reveals the installer's username, UID, GID, and group memberships, providing reconnaissance for follow-on attacks and confirming the callback for the operator.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownfmt-date-lite1.0.0 (affected)

References

vendor

Browse GCVE Records

76,198 records in the GCVE database · Updated August 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›