VDB
GCVE-110-OSM-2026-9323
GCVE-110-OSM-2026-9323
Advisory PublishedCVSS 8.8/10
This package contains a preinstall hook that executes a curl on an IP address on installation — a classic supply-chain attack pattern where installation triggers a callback to an attacker-controlled server. The IP address is a raw internal/private-range-adjacent IP used as a C2 or OAST endpoint to confirm successful installation or to fetch a second-stage payload. The publisher '404c3s4r' has exactly one package, no repository, no description, and a protonmail address — all hallmarks of a throwaway account. The package version 9.2.0 with no history or dependents signals version inflation to appear established. The security holding flag confirms this has already been flagged for removal.
ENTRY
- Preinstall Script in package.json
DESTINATION
- 1 fetched-payload (urls)
(values recorded in verified_iocs)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @404c3s4r/testxxx | all (affected) | — |
Aliases
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.