VDB
GCVE-110-OSM-2026-9643
GCVE-110-OSM-2026-9643
Advisory PublishedCVSS 9.6/10
This package contains a textbook reverse shell payload executing on postinstall. The file postinstall.js spawns a sh process and pipes its stdin/stdout/stderr to a TCP socket connecting to an ngrok tunnel acting as the attacker's C2. Any developer who installs this package gives the attacker an interactive shell on their machine. The package has no description, no repository, no author metadata, and a name ('discord-vibegrations-api-helpers') constructed to appear plausible while being completely fabricated. The attacker model is clear: supply-chain compromise via a plausible-looking Discord utility package that silently backdoors the victim's machine on install.
ENTRY
postinstall.js (install-hook: node postinstall.js)
- Install Hook Executes Local JS File in package.json
EXFIL
- Suspicious Domain in postinstall.js: "ngrok.io"
ADDITIONAL FINDINGS
- Shell Command Execution in postinstall.js: "require("child_process")"
- Ngrok Tunneling Service in postinstall.js: "ngrok.io"
PAYLOAD FILES
postinstall.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | discord-vibegrations-api-helpers | all (affected) | — |
Aliases
Browse GCVE Records
67,857 records in the GCVE database · Updated August 15, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.