VDB

GCVE-110-OSM-2026-9311

GCVE-110-OSM-2026-9311
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published July 29, 2026
This package self-identifies explicitly as a dependency-confusion proof-of-concept in both its npm description ('PoC package for internal dependency-confusion security demo') and in postinstall.js console output. Despite the self-labeling, the code does make a real out-of-band callback to 'llhvrrffsffmousfvteqie2heq3c7rl55.oast.fun' transmitting os.userInfo().username in the query parameter, which constitutes actual data exfiltration regardless of intent. Per osmalyze policy, packages self-identifying as security tests are classified suspicious-but-benign rather than malicious, since submitting bounty/demo artifacts pollutes the OSM database. The attacker model is dependency confusion demonstration, not adversarial compromise, and the payload is minimal and declared. ENTRY postinstall.js (install-hook: node ./postinstall.js) - Install Hook Executes Local JS File in package.json DESTINATION - custom-c2: llhvrrffsffmousfvteqie2heq3c7rl55.oast.fun (primary, plaintext) in postinstall.js EXFIL - OAST/Interactsh Exfiltration in postinstall.js: ".oast.fun" - Network Request in postinstall.js: "https.get(" - System Information Collection in postinstall.js: "os.userInfo()" - DNS Lookup in postinstall.js: "dns.resolve(" - Suspicious Domain in postinstall.js: "oast.fun" ADDITIONAL FINDINGS - Brand New Package - Rapid Version Publishing PAYLOAD FILES postinstall.js INDICATORS (IOCs) - payloadFileHash: 7afe96ec6f295facf720d5a234fb8df3424d00112b8a73c122dbbf99db6f8330

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknown@finxsecdemo/utilsall (affected)

References

advisory
vendor

Browse GCVE Records

75,823 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›