VDB

GCVE-110-OSM-2026-9643

GCVE-110-OSM-2026-9643
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 4, 2026
This package contains a textbook reverse shell payload executing on postinstall. The file postinstall.js spawns a sh process and pipes its stdin/stdout/stderr to a TCP socket connecting to an ngrok tunnel acting as the attacker's C2. Any developer who installs this package gives the attacker an interactive shell on their machine. The package has no description, no repository, no author metadata, and a name ('discord-vibegrations-api-helpers') constructed to appear plausible while being completely fabricated. The attacker model is clear: supply-chain compromise via a plausible-looking Discord utility package that silently backdoors the victim's machine on install. ENTRY postinstall.js (install-hook: node postinstall.js) - Install Hook Executes Local JS File in package.json EXFIL - Suspicious Domain in postinstall.js: "ngrok.io" ADDITIONAL FINDINGS - Shell Command Execution in postinstall.js: "require("child_process")" - Ngrok Tunneling Service in postinstall.js: "ngrok.io" PAYLOAD FILES postinstall.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowndiscord-vibegrations-api-helpersall (affected)

References

advisory
vendor

Browse GCVE Records

67,857 records in the GCVE database · Updated August 15, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›