VDB

GCVE-110-OSM-2026-10624

GCVE-110-OSM-2026-10624
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 17, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code, install-time execution. ENTRY scripts/preinstall-check.cjs (install-hook: node scripts/preinstall-check.cjs) - Install Hook Executes Local JS File in package.json LOOT - Browser Data Theft in dist/core.cjs: "firefox\/(\d+)/))&&parseInt(_0x101a91[0x1],0xa)>=0x1f||typeof navigator!==_0x58e..." PERSISTENCE - Startup Persistence in dist/core.cjs: "startup\" DESTINATION - reconstructed: http://localhost:9999 (primary, reconstructed) in dist/core.cjs - custom-c2: localhost:9999 (reconstructed) in dist/core.cjs - custom-c2: http://[ (plaintext) in dist/core.cjs - custom-c2: https://doh.pub/reso (plaintext) in dist/core.cjs - custom-c2: https://dns.google/r (plaintext) in dist/core.cjs - custom-c2: http://json-schema.o (plaintext) in dist/core.cjs - custom-c2: https://claude.ai/se (plaintext) in dist/core.cjs - custom-c2: https://api.openai.c (plaintext) in dist/core.cjs (+17 more) EXFIL - Environment Variable Exfiltration in dist/core.cjs: "process.env.CODEX_PATH||_0x10b7d1(0x1475),_0x5b27f6=Date[_0x10b7d1(0x2863)]();if..." - Data Encoding for Exfiltration in dist/core.cjs: "btoa(" - Dynamic C2 Endpoint Construction in dist/core.cjs: "function _0x390755(){return _0x3464ec&&(_0x1c8951=(0x0,_0x3464ec[__getOwnPropNam..." - Network Request in dist/core.cjs: "fetch('https:" OBFUSCATION - Dynamic Base64 Decoding in dist/core.cjs: "atob(_0x316d39)" - Obfuscation: augmented proxied array function replacements in dist/core.cjs - Obfuscation: augmented proxied array function replacements in dist/index.cjs - Hex Encoded Strings in dist/core.cjs: "'\x20\x20\x20\x20\x20\x20\x0a\x20\x20\x20\x20\x20\x20'" - String Array Obfuscation in dist/core.cjs: "_0x230fd2[_0x3dd9cc-0x1]" - Unicode Escape Obfuscation in dist/core.cjs: "\u06D3\u06D5\u06E5\u06E6\u06EE\u06EF\u06FA" - Unicode Escape Obfuscation in dist/index.cjs: "\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20" - Deobfuscation Failed in dist/index.cjs (+3 more) ADDITIONAL FINDINGS - Reconstructed Obfuscated URL in dist/core.cjs: "http://localhost:9999" - Dynamic Code Execution in dist/core.cjs: "new Function(''+" - Shell Command Execution in dist/core.cjs: "require('child_process')" - Indirect Function Constructor Access in dist/core.cjs: "['constructor']" - Shell Command Variable Setup in dist/core.cjs: "WindowsCmdSh" PAYLOAD FILES dist/core.cjs INDICATORS (IOCs) - urls: https://memory.whalent.com, https://memory.whale, https://registry.npm - domains: memory.whalent.com, nt.com, js.org - payloadFileHash: 2282a25c4f0824fe7f711facf5c5ecd5e7c6949537e2da665fb9d6a569f36a95

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@whalent/agent0.3.234 (affected)

References

advisory
vendor

Browse GCVE Records

867 records in the GCVE database · Updated September 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›