VDB

MAL-2026-14353

MAL-2026-14353 PUBLISHED CVSS 9.300000190734863 CRITICAL

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (22abe9bf1ccb266833585bda205a07bc5c9a728763a733aa48b08fe50b640b4e) All three npm lifecycle hooks (preinstall, install, postinstall) invoke install.js, which POSTs the installer's hostname, OS username, current working directory, timestamp, and hook name to a hardcoded webhook.site collector at https://webhook.site/df384ffa-1094-4bbf-a202-e8b345b3ed18/gfe. The exfiltration fires automatically on `npm install` with no caller consent and no configuration. The package's `main` is a no-op `createWatcher` stub, so a build that resolves this scoped name silently succeeds while host identifiers are leaked. The scoped `@gfe/*` name combined with the no-op stub and the install-time beacon is the canonical dependency-confusion shape: any organization whose private `@gfe/lx-watcher` resolves against the public registry leaks host, username, and install-path metadata to the author-controlled collector.

Risk Scores

CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
gfelx-watcher
gfelx-watcher1.5.3, 1.5.4

Timeline

  • Aug 21, 2026 CVE Published
  • Aug 21, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›