VDB

GCVE-110-OSM-2026-9338

GCVE-110-OSM-2026-9338
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published July 31, 2026
This package declares a direct dependency on 'streak-metrics-core', which is confirmed malicious in both the OSM database and independent intelligence sources. The package itself is a thin wrapper ('pure browser-safe core, plus an optional Node-only cached server entry') with no source repository and no author metadata, consistent with a dependency-confusion or supply-chain staging package whose sole purpose is to pull in the known-malicious dependency. The absence of any entrypoint or exfil heuristics in the scan is expected if the malicious payload is entirely within the dependency, not this package's own source. The combination of a confirmed-malicious dependency, no repository, no author, and a brand-new package with no described prior history makes this almost certainly a vehicle for delivering streak-metrics-core's payload. ADDITIONAL FINDINGS - Malicious Dependency Detected in package.json - Malicious Dependency Detected (OSM) in package.json

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownsvelte-streak-metricall (affected)

References

advisory
vendor

Browse GCVE Records

75,836 records in the GCVE database · Updated August 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›