VDB
GCVE-110-OSM-2026-10624
GCVE-110-OSM-2026-10624
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code, install-time execution.
ENTRY
scripts/preinstall-check.cjs (install-hook: node scripts/preinstall-check.cjs)
- Install Hook Executes Local JS File in package.json
LOOT
- Browser Data Theft in dist/core.cjs: "firefox\/(\d+)/))&&parseInt(_0x101a91[0x1],0xa)>=0x1f||typeof navigator!==_0x58e..."
PERSISTENCE
- Startup Persistence in dist/core.cjs: "startup\"
DESTINATION
- reconstructed: http://localhost:9999 (primary, reconstructed) in dist/core.cjs
- custom-c2: localhost:9999 (reconstructed) in dist/core.cjs
- custom-c2: http://[ (plaintext) in dist/core.cjs
- custom-c2: https://doh.pub/reso (plaintext) in dist/core.cjs
- custom-c2: https://dns.google/r (plaintext) in dist/core.cjs
- custom-c2: http://json-schema.o (plaintext) in dist/core.cjs
- custom-c2: https://claude.ai/se (plaintext) in dist/core.cjs
- custom-c2: https://api.openai.c (plaintext) in dist/core.cjs
(+17 more)
EXFIL
- Environment Variable Exfiltration in dist/core.cjs: "process.env.CODEX_PATH||_0x10b7d1(0x1475),_0x5b27f6=Date[_0x10b7d1(0x2863)]();if..."
- Data Encoding for Exfiltration in dist/core.cjs: "btoa("
- Dynamic C2 Endpoint Construction in dist/core.cjs: "function _0x390755(){return _0x3464ec&&(_0x1c8951=(0x0,_0x3464ec[__getOwnPropNam..."
- Network Request in dist/core.cjs: "fetch('https:"
OBFUSCATION
- Dynamic Base64 Decoding in dist/core.cjs: "atob(_0x316d39)"
- Obfuscation: augmented proxied array function replacements in dist/core.cjs
- Obfuscation: augmented proxied array function replacements in dist/index.cjs
- Hex Encoded Strings in dist/core.cjs: "'\x20\x20\x20\x20\x20\x20\x0a\x20\x20\x20\x20\x20\x20'"
- String Array Obfuscation in dist/core.cjs: "_0x230fd2[_0x3dd9cc-0x1]"
- Unicode Escape Obfuscation in dist/core.cjs: "\u06D3\u06D5\u06E5\u06E6\u06EE\u06EF\u06FA"
- Unicode Escape Obfuscation in dist/index.cjs: "\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20"
- Deobfuscation Failed in dist/index.cjs
(+3 more)
ADDITIONAL FINDINGS
- Reconstructed Obfuscated URL in dist/core.cjs: "http://localhost:9999"
- Dynamic Code Execution in dist/core.cjs: "new Function(''+"
- Shell Command Execution in dist/core.cjs: "require('child_process')"
- Indirect Function Constructor Access in dist/core.cjs: "['constructor']"
- Shell Command Variable Setup in dist/core.cjs: "WindowsCmdSh"
PAYLOAD FILES
dist/core.cjs
INDICATORS (IOCs)
- urls: https://memory.whalent.com, https://memory.whale, https://registry.npm
- domains: memory.whalent.com, nt.com, js.org
- payloadFileHash: 2282a25c4f0824fe7f711facf5c5ecd5e7c6949537e2da665fb9d6a569f36a95
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @whalent/agent | 0.3.234 (affected) | — |
Aliases
Browse GCVE Records
867 records in the GCVE database · Updated September 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.