VDB

GCVE-110-OSM-2026-10625

GCVE-110-OSM-2026-10625
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 17, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, network activity, obfuscated code, install-time execution. ENTRY dist/vendor/node-pty/lib/index.js (main: ./lib/index.js) - Install Hook Executes Local JS File in dist/vendor/node-pty/package.json: ""install": "node scripts/prebuild.js || node-gyp rebuild"" - Install Hook Executes Local JS File in package.json: ""postinstall": "node dist/postinstall.js || true"" - Postinstall Script in dist/vendor/node-pty/package.json: ""postinstall": "node scripts/post-install.js"" PERSISTENCE - Startup Persistence in dist/index.js: ".bashrc" DESTINATION - reconstructed: https://registry.npmjs.org/codeam-cli/latest (primary, reconstructed) in dist/index.js - custom-c2: registry.npmjs.org (reconstructed) in dist/index.js - custom-c2: https://api.kimi.com/coding/ (plaintext) in dist/index.js - custom-c2: https://dev-api.codeagent-mobile.com (plaintext) in dist/index.js - custom-c2: http://yandex.com/bots (plaintext) in dist/index.js - custom-c2: https://us.i.posthog.com (plaintext) in dist/index.js - custom-c2: https://eu.i.posthog.com (plaintext) in dist/index.js - custom-c2: https://posthog.com/docs/feature-flags/best-practices (plaintext) in dist/index.js (+52 more) EXFIL - Environment Variable Exfiltration in dist/index.js: "process.env.HEADROOM_STATS_POLL_INTERVAL_MS ?? "30000") || 3e4); this.timer = se..." - Corporate Environment Targeting in dist/index.js: "tModel = null; for (const line of raw.split("\n").filter" - HTTP Data Exfiltration in dist/index.js: "process.cwd(), parsed.filePath, reviewAction ); await ctx.relay.sendResult( cmd...." - Data Encoding for Exfiltration in dist/index.js: "encodeURIComponent(this.apiKey" - Curl/Wget Pipe to Shell in dist/index.js: "curl -fsSL https://claude.ai/install.sh | bash" - Network Request in dist/index.js: "fetch("http:" - System Information Collection in dist/index.js: "os.homedir()" - System Information Collection in dist/vendor/node-pty/lib/index.js: "process.platform" (+2 more) OBFUSCATION - Dynamic Base64 Decoding in dist/index.js: "Buffer.from(padded, "base64")" - Obfuscation: function to array replacements in dist/index.js - Obfuscation patterns: unicodeHeavy, hexHeavy in dist/index.js - recovered 1 urls, 1 domains from decoded/deobfuscated content ADDITIONAL FINDINGS - Reconstructed Obfuscated URL in dist/index.js: "https://registry.npmjs.org/codeam-cli/latest" - Binary: Injection in dist/vendor/node-pty/prebuilds/win32-arm64/conpty/OpenConsole.exe: "VirtualAlloc" - Dynamic Code Execution in dist/index.js: "exec(uuid)" - Shell Command Execution in dist/index.js: "child_process").spawn" - Silent Process Execution in dist/index.js: "stdio: "ignore"" - Shell Command Variable Setup in dist/index.js: "Windows = process.platform === "win32"; const cmd = isWindows ? "powershell.exe"..." (+7 more) PAYLOAD FILES dist/index.js INDICATORS (IOCs) - ipv4: 1.1.1.1, 6.0.0.0 - urls: https://codeagent-mobile.com, https://claude.ai/code, https://api.codeagent-mobile.com/api/self-hosted/enroll.sh, https://code.claude.com/docs/en/quickstart, https://api.codeagent-mobile.com` (+3 more) - domains: codeagent-mobile.com, enroll.sh, code.claude.com, plugins.jetbrains.com, www.microsoft.com0 (+7 more) - emails: URL@api.codeagent-mobile.com, wires@runner.ts, repo@.devfile.yaml - binaryHashes: f518869c39b9e2910fc88df0261a234724da8a0453d6738303cb7bc696084875, 4d89696a2478db71c2f5e1acf50c864e46de78e3dc811d6c43f709a9f17b1f28, c56d15ff6a90fa2c221c7bb468be43b8f12861745c0b99e781dd4bcacde0bd96, 501db91ce52257dd17f0518c60da483948c0b6d9dc0b0ac5ce65fe293f97868d, bcb5687911c1fe061fec9b0f89ef9ef3f5be5326888eecce70a4f653e9a7ec97 (+3 more) - payloadFileHash: d6eeeaa584532ff1e2599faf65137961f6d593b8a32abc4771a8cd95808717c3

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowncodeam-cli2.61.14 (affected)

References

advisory
vendor

Browse GCVE Records

867 records in the GCVE database · Updated September 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›