VDB

GCVE-110-OSM-2026-8319

GCVE-110-OSM-2026-8319
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published July 18, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, install-time execution. ENTRY scripts/install-check.cjs (install-hook: node scripts/install-check.cjs) - Install Hook Executes Local JS File in package.json - Hidden NPM Install in scripts/install-check.cjs EXFIL - System Information Exfiltration in scripts/install-check.cjs: "__dirname, '..'); const peerDir = path.join(pkgRoot, '.peer'); function readPack..." ADDITIONAL FINDINGS - Shell Command Execution in scripts/install-check.cjs: "require('child_process')" - Brand New Package - Rapid Version Publishing SECONDARY PACKAGES (hidden install) - --omit [OSM: clean] in scripts/install-check.cjs PAYLOAD FILES scripts/install-check.cjs INDICATORS (IOCs) - urls: https://ts-eslint.vercel.app/config/clob-math.json - domains: ts-eslint.vercel.app - payloadFileHash: 41d2656dc9508eb4f36abead0e471b0a1157342d52e520e736fb183759f60f5e

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownts-vitest1.1.3 (affected)

References

vendor

Browse GCVE Records

75,797 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›