VDB

GCVE-110-OSM-2026-9323

GCVE-110-OSM-2026-9323
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published July 31, 2026
This package contains a preinstall hook that executes a curl on an IP address on installation — a classic supply-chain attack pattern where installation triggers a callback to an attacker-controlled server. The IP address is a raw internal/private-range-adjacent IP used as a C2 or OAST endpoint to confirm successful installation or to fetch a second-stage payload. The publisher '404c3s4r' has exactly one package, no repository, no description, and a protonmail address — all hallmarks of a throwaway account. The package version 9.2.0 with no history or dependents signals version inflation to appear established. The security holding flag confirms this has already been flagged for removal. ENTRY - Preinstall Script in package.json DESTINATION - 1 fetched-payload (urls) (values recorded in verified_iocs)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@404c3s4r/testxxxall (affected)

References

advisory
vendor

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›