VDB
GCVE-110-OSM-2026-9338
GCVE-110-OSM-2026-9338
Advisory PublishedCVSS 8.8/10
This package declares a direct dependency on 'streak-metrics-core', which is confirmed malicious in both the OSM database and independent intelligence sources. The package itself is a thin wrapper ('pure browser-safe core, plus an optional Node-only cached server entry') with no source repository and no author metadata, consistent with a dependency-confusion or supply-chain staging package whose sole purpose is to pull in the known-malicious dependency. The absence of any entrypoint or exfil heuristics in the scan is expected if the malicious payload is entirely within the dependency, not this package's own source. The combination of a confirmed-malicious dependency, no repository, no author, and a brand-new package with no described prior history makes this almost certainly a vehicle for delivering streak-metrics-core's payload.
ADDITIONAL FINDINGS
- Malicious Dependency Detected in package.json
- Malicious Dependency Detected (OSM) in package.json
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | svelte-streak-metric | all (affected) | — |
Aliases
Browse GCVE Records
75,836 records in the GCVE database · Updated August 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.