PT-2026-69857 · Npm · Use-Context-Selector

CVE-2026-48158

·

Published

2026-08-10

·

Updated

2026-08-11

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions use-context-selector (affected versions not specified)
Description Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34, the default branch contained malicious commits that executed remote attacker-controlled code on developer machines during npm install. The issue involved the addition of src/install.js, which was integrated into the postinstall script. This script fetched a JavaScript payload from an attacker-controlled HTTPS endpoint, disabled TLS verification, and evaluated the response as code. The execution specifically targeted developer workstations, deliberately skipping CI and cloud or serverless environments. Although the commits were removed via force-push, the code remains active in local clones, forks, and direct-SHA URLs. This can lead to a full compromise of any resource reachable from a Node process with the user's permissions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Clean all local clones of the repository. Rotate every credential reachable from the affected machine. Audit account activity since 2026-05-18 15:57:18.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48158

Affected Products

Use-Context-Selector