VDB

GCVE-110-OSM-2025-834

GCVE-110-OSM-2025-834
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published December 19, 2025
Malicious package detected with 7 suspicious findings: - OAST/Interactsh Exfiltration: Uses out-of-band application security testing (OAST) or data exfiltration services - Suspicious Domain: Connects to potentially malicious domains - Preinstall Script: Package has a preinstall script - Has Install Scripts: Package has preinstall, install, or postinstall scripts - Recently Published Package: Package was published 0 days ago - Missing or Empty Description: Package has no meaningful description - No Source Repository: Package has no linked source repository Uses out-of-band application security testing (OAST) or data exfiltration services (e.g., "oastify.com"). Connects to potentially malicious domains (e.g., "oastify.com") Extracted IOCs: - domains: xrs8asm4xktl5idlrltj79x4xv3mrif7.oastify.com, burpcollaborator.net

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownshakti20261all (affected)

References

vendor

Browse GCVE Records

831 records in the GCVE database · Updated September 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›