VDB

GCVE-110-OSM-2026-10622

GCVE-110-OSM-2026-10622
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 17, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, network activity, obfuscated code. ENTRY cli.js (bin: ./cli.js) - Hidden NPM Install in service/windows.js: "execSync('npm install -g pm2'" PERSISTENCE - Startup Persistence in yeaft/attachments.js: ".bashrc" - Startup Persistence in yeaft/engine.js: ".profile" DESTINATION - custom-c2: https://api.tavily.com/usage (primary, plaintext) in yeaft/config-api.js - custom-c2: https://... (plaintext) in yeaft/tools/web-search.js - custom-c2: https://tavily.com (plaintext) in yeaft/tools/web-search.js - custom-c2: https://api.tavily.com/search (plaintext) in yeaft/tools/web-search.js - custom-c2: https://duckduckgo.com (plaintext) in yeaft/tools/web-search.js - custom-c2: api.tavily.com (plaintext) in yeaft/config-api.js - custom-c2: tavily.com (plaintext) in yeaft/config-api.js - custom-c2: html.duckduckgo.com (plaintext) in yeaft/tools/web-search.js (+2 more) EXFIL - Corporate Environment Targeting in expert-roles.js: "tmosphere? |\n| Deletion test" - Corporate Environment Targeting in llm-config-cli.js: "tModel].filter(Boolean)) { if (!allowUnknown && !discoveredIds.includes" - Corporate Environment Targeting in providers/copilot-models.js: "tModelsCacheForTests() { _cache = null; _inflight = null; } /** Test" - Environment Variable Exfiltration in providers/copilot.js: "process.env.COPILOT_YOLO === '1'; const ACP_PROTOCOL_VERSION = 1; // Boot handsh..." - Corporate Environment Targeting in providers/copilot.js: "tModified: toEpochMs(r.updated_at) || toEpochMs(r.created_at), }; }).filter" - Reverse Shell in terminal.js: "pty.spawn(" - Environment Variable Exfiltration in yeaft/cli.js: "process.env.YEAFT_DIR || null; await fetch" - Corporate Environment Targeting in yeaft/llm/anthropic.js: "tModelEffortOptions(model, effortContext).includes" (+16 more) OBFUSCATION - Dynamic Base64 Decoding in proxy.js: "Buffer.from(body, 'base64')" - Dynamic Base64 Decoding in yeaft/conversation/persist.js: "Buffer.from(value, 'base64')" - Dynamic Base64 Decoding in yeaft/work-center/attachments.js: "Buffer.from(data, 'base64')" - Decoded Base64 Content in [deobfuscated] proxy.js - Strings Extracted from Deobfuscated Code in proxy.js - Deobfuscation Failed in yeaft/conversation/persist.js - Deobfuscation Failed in yeaft/work-center/attachments.js ADDITIONAL FINDINGS - Stealth Background Process Spawning in cli.js: "spawn('wscript.exe', [vbsPath], { detached: true, stdio: 'ignore', windowsHide: ..." - Download Execute Delete Pattern in connection/upgrade-worker-template.js: "writeFileSync(dest, f.data), 'write ' + f.path); } log('Copied ' + files.length ..." - Dynamic Code Execution in check-node-version.js: "exec(v)" - Shell Command Execution in cli.js: "execSync(" - Silent Process Execution in cli.js: "stdio: 'ignore'" - Detached Child Process Payload in cli.js: "spawn('wscript.exe', [vbsPath], { detached: true" (+2 more) SECONDARY PACKAGES (hidden install) - -g [OSM: clean] in service/windows.js PAYLOAD FILES providers/copilot.js (+ service/windows.js, yeaft/tools/web-search.js) INDICATORS (IOCs) - urls: https://api.githubcopilot.com/models, https://pkg.yeaft.com/, https://api.githubcopilot.com, https://models.dev/api.json, https://api.deepseek.com (+1 more) - domains: your-server.com, ctx.ws, models.dev, api.githubcopilot.com, pkg.yeaft.com (+2 more) - emails: i.e.@conversationMessages.length, drain@engine.js, work-center@yeaft.local - payloadFileHash: 54f5d18b9e6a30874c8c231f60aafd136a09d693ac3b0a9cc4c9ebad8797ebe6

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@yeaft/webchat-agent1.0.172 (affected)

References

advisory
vendor

Browse GCVE Records

3,587 records in the GCVE database · Updated September 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›