VDB

GCVE-110-OSM-2026-10516

GCVE-110-OSM-2026-10516
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 13, 2026
Malicious package detected. Behaviors: code execution, obfuscated code. ENTRY index.js (main: ./index.js) OBFUSCATION - Obfuscation: augmented proxied array function replacements in build/power-assert-plus.js - Obfuscation (osm-deobfuscator): obfuscator-io in build/power-assert-plus.js - Strings Extracted from Deobfuscated Code in build/power-assert-plus.js - Obfuscation patterns: hexVariables in build/power-assert-plus.js ADDITIONAL FINDINGS - Stealth Background Process Spawning in index.js: "spawn("node", [powerAssertion, JSON.stringify(args)], { detached: true, stdio: "..." - Shell Command Execution in index.js: "require("child_process")" - Silent Process Execution in index.js: "stdio: "ignore"" - Detached Child Process Payload in index.js: "spawn("node", [powerAssertion, JSON.stringify(args)], { detached: true" PAYLOAD FILES index.js (+ build/power-assert-plus.js)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownpower-assert-plusall (affected)

References

vendor

Browse GCVE Records

417 records in the GCVE database · Updated August 26, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›