VDB
GCVE-110-OSM-2026-9311
GCVE-110-OSM-2026-9311
Advisory PublishedCVSS 5.4/10
This package self-identifies explicitly as a dependency-confusion proof-of-concept in both its npm description ('PoC package for internal dependency-confusion security demo') and in postinstall.js console output. Despite the self-labeling, the code does make a real out-of-band callback to 'llhvrrffsffmousfvteqie2heq3c7rl55.oast.fun' transmitting os.userInfo().username in the query parameter, which constitutes actual data exfiltration regardless of intent. Per osmalyze policy, packages self-identifying as security tests are classified suspicious-but-benign rather than malicious, since submitting bounty/demo artifacts pollutes the OSM database. The attacker model is dependency confusion demonstration, not adversarial compromise, and the payload is minimal and declared.
ENTRY
postinstall.js (install-hook: node ./postinstall.js)
- Install Hook Executes Local JS File in package.json
DESTINATION
- custom-c2: llhvrrffsffmousfvteqie2heq3c7rl55.oast.fun (primary, plaintext) in postinstall.js
EXFIL
- OAST/Interactsh Exfiltration in postinstall.js: ".oast.fun"
- Network Request in postinstall.js: "https.get("
- System Information Collection in postinstall.js: "os.userInfo()"
- DNS Lookup in postinstall.js: "dns.resolve("
- Suspicious Domain in postinstall.js: "oast.fun"
ADDITIONAL FINDINGS
- Brand New Package
- Rapid Version Publishing
PAYLOAD FILES
postinstall.js
INDICATORS (IOCs)
- payloadFileHash: 7afe96ec6f295facf720d5a234fb8df3424d00112b8a73c122dbbf99db6f8330
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @finxsecdemo/utils | all (affected) | — |
Aliases
Browse GCVE Records
75,823 records in the GCVE database · Updated August 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.