VDB
GCVE-110-OSM-2026-10625
GCVE-110-OSM-2026-10625
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution, network activity, obfuscated code, install-time execution.
ENTRY
dist/vendor/node-pty/lib/index.js (main: ./lib/index.js)
- Install Hook Executes Local JS File in dist/vendor/node-pty/package.json: ""install": "node scripts/prebuild.js || node-gyp rebuild""
- Install Hook Executes Local JS File in package.json: ""postinstall": "node dist/postinstall.js || true""
- Postinstall Script in dist/vendor/node-pty/package.json: ""postinstall": "node scripts/post-install.js""
PERSISTENCE
- Startup Persistence in dist/index.js: ".bashrc"
DESTINATION
- reconstructed: https://registry.npmjs.org/codeam-cli/latest (primary, reconstructed) in dist/index.js
- custom-c2: registry.npmjs.org (reconstructed) in dist/index.js
- custom-c2: https://api.kimi.com/coding/ (plaintext) in dist/index.js
- custom-c2: https://dev-api.codeagent-mobile.com (plaintext) in dist/index.js
- custom-c2: http://yandex.com/bots (plaintext) in dist/index.js
- custom-c2: https://us.i.posthog.com (plaintext) in dist/index.js
- custom-c2: https://eu.i.posthog.com (plaintext) in dist/index.js
- custom-c2: https://posthog.com/docs/feature-flags/best-practices (plaintext) in dist/index.js
(+52 more)
EXFIL
- Environment Variable Exfiltration in dist/index.js: "process.env.HEADROOM_STATS_POLL_INTERVAL_MS ?? "30000") || 3e4); this.timer = se..."
- Corporate Environment Targeting in dist/index.js: "tModel = null; for (const line of raw.split("\n").filter"
- HTTP Data Exfiltration in dist/index.js: "process.cwd(), parsed.filePath, reviewAction ); await ctx.relay.sendResult( cmd...."
- Data Encoding for Exfiltration in dist/index.js: "encodeURIComponent(this.apiKey"
- Curl/Wget Pipe to Shell in dist/index.js: "curl -fsSL https://claude.ai/install.sh | bash"
- Network Request in dist/index.js: "fetch("http:"
- System Information Collection in dist/index.js: "os.homedir()"
- System Information Collection in dist/vendor/node-pty/lib/index.js: "process.platform"
(+2 more)
OBFUSCATION
- Dynamic Base64 Decoding in dist/index.js: "Buffer.from(padded, "base64")"
- Obfuscation: function to array replacements in dist/index.js
- Obfuscation patterns: unicodeHeavy, hexHeavy in dist/index.js
- recovered 1 urls, 1 domains from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Reconstructed Obfuscated URL in dist/index.js: "https://registry.npmjs.org/codeam-cli/latest"
- Binary: Injection in dist/vendor/node-pty/prebuilds/win32-arm64/conpty/OpenConsole.exe: "VirtualAlloc"
- Dynamic Code Execution in dist/index.js: "exec(uuid)"
- Shell Command Execution in dist/index.js: "child_process").spawn"
- Silent Process Execution in dist/index.js: "stdio: "ignore""
- Shell Command Variable Setup in dist/index.js: "Windows = process.platform === "win32"; const cmd = isWindows ? "powershell.exe"..."
(+7 more)
PAYLOAD FILES
dist/index.js
INDICATORS (IOCs)
- ipv4: 1.1.1.1, 6.0.0.0
- urls: https://codeagent-mobile.com, https://claude.ai/code, https://api.codeagent-mobile.com/api/self-hosted/enroll.sh, https://code.claude.com/docs/en/quickstart, https://api.codeagent-mobile.com` (+3 more)
- domains: codeagent-mobile.com, enroll.sh, code.claude.com, plugins.jetbrains.com, www.microsoft.com0 (+7 more)
- emails: URL@api.codeagent-mobile.com, wires@runner.ts, repo@.devfile.yaml
- binaryHashes: f518869c39b9e2910fc88df0261a234724da8a0453d6738303cb7bc696084875, 4d89696a2478db71c2f5e1acf50c864e46de78e3dc811d6c43f709a9f17b1f28, c56d15ff6a90fa2c221c7bb468be43b8f12861745c0b99e781dd4bcacde0bd96, 501db91ce52257dd17f0518c60da483948c0b6d9dc0b0ac5ce65fe293f97868d, bcb5687911c1fe061fec9b0f89ef9ef3f5be5326888eecce70a4f653e9a7ec97 (+3 more)
- payloadFileHash: d6eeeaa584532ff1e2599faf65137961f6d593b8a32abc4771a8cd95808717c3
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | codeam-cli | 2.61.14 (affected) | — |
Aliases
Browse GCVE Records
867 records in the GCVE database · Updated September 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.