VDB
GCVE-110-OSM-2026-10626
GCVE-110-OSM-2026-10626
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code.
ENTRY
dist/vibelet.mjs (bin: dist/vibelet.mjs)
PERSISTENCE
- Startup Persistence in dist/index.cjs: ".profile"
- Startup Persistence in dist/web/assets/index-BiSnL70b.js: ".profile"
DESTINATION
- reconstructed: https://react.dev/errors/null (primary, reconstructed) in dist/web/assets/index-BiSnL70b.js
- reconstructed: https://github.com/syntax-tree/hast-util-to-jsx-runtime#cannot-parse-style-attribute (reconstructed) in dist/web/assets/index-BiSnL70b.js
- custom-c2: react.dev (reconstructed) in dist/web/assets/index-BiSnL70b.js
- custom-c2: github.com (reconstructed) in dist/vibelet.mjs
- tunnel: https://abc.trycloudflare.com (plaintext) in dist/vibelet.mjs
- custom-c2: https://exp.host/--/api/v2/push/send (plaintext) in dist/index.cjs
- custom-c2: https://exp.host/--/api/v2/push/getReceipts (plaintext) in dist/index.cjs
- custom-c2: https://www.cl.cam.ac.uk/%7Emgk25/ucs/utf8_check.c (plaintext) in dist/vibelet.mjs
(+19 more)
EXFIL
- OAST/Interactsh Exfiltration in dist/index.cjs: ".trycloudflare.com"
- Environment Variable Exfiltration in dist/vibelet.mjs: "process.env.VIBE_CLAUDE_DRIVER ? normalizeDriver(process.env.VIBE_CLAUDE_DRIVER)..."
- OAST/Interactsh Exfiltration in dist/vibelet.mjs: ".trycloudflare.com"
- Corporate Environment Targeting in dist/vibelet.mjs: "tModeForData = function getBestModeForData (dataStr) { if (Regex.test"
- Corporate Environment Targeting in dist/web/assets/apache-Pmp26Uib.js: "tMod|LastModifiedFactor|MaxExpire))\\\\b"},{"captures":{"1":{"name":"keyword.cer..."
- Corporate Environment Targeting in dist/web/assets/applescript-Co6uUVPk.js: "tmost|version)\\\\b","name":"support.constant.standard-suite.applescript"},{"mat..."
- Corporate Environment Targeting in dist/web/assets/blade-D4QpJJKB.js: "tmore)|bson_((?:de|en)code))\\\\b","name":"support.function.mongo.php"},{"match"
- Corporate Environment Targeting in dist/web/assets/emacs-lisp-C9XAeP06.js: "magenta|term-color-red|term-color-white|term-color-yellow|term-underline|term|te..."
(+17 more)
OBFUSCATION
- Obfuscation: augmented proxied array function replacements in dist/index.cjs
- Obfuscation: function to array replacements in dist/index.cjs
- Dynamic Base64 Decoding in dist/web/assets/index-BiSnL70b.js: "atob(o)"
- Base64 Encoded Payload in dist/index.cjs: "'laOGicaGBwv0Ag9KoIaNue9tvcCScIaGicbWyxrOoIaNl2HVB2SVy2XHDwrLl3bLCM1PC3nPB24TCMv..."
- String Array Obfuscation in dist/index.cjs: "['0','1','2','3','4','5','6','7','8','9','A','B','C','D','E','F','G','H','I','J'..."
- Unicode Escape Obfuscation in dist/index.cjs: "\x0a\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20"
- String Array Obfuscation in dist/vibelet.mjs: "[ '0', '1', '2', '3', '4', '5', '6', '7', '8', '9', 'A', 'B', 'C', 'D', 'E', 'F'..."
- String Array Obfuscation in dist/web/assets/asciidoc-Ve4PFQV2.js: "["html","yaml","csv","css","ini","java","lua","make","perl","r","ruby","php","sq..."
(+28 more)
ADDITIONAL FINDINGS
- Download Execute Delete Pattern in dist/web/assets/blade-D4QpJJKB.js: "executable|link|readable|writ(e)?able)|disk_(free|total)_space|diskfreespace|dir..."
- Reconstructed Obfuscated URL in dist/web/assets/index-BiSnL70b.js: "https://react.dev/errors/null"
- Indirect Function Constructor Access in dist/index.cjs: "['constructor']"
- Dynamic Code Execution in dist/vibelet.mjs: "exec(str)"
- Silent Process Execution in dist/vibelet.mjs: "stdio: 'ignore'"
- Suspicious TLD Domain in dist/vibelet.mjs: "https://www.cl.cam"
(+1 more)
PAYLOAD FILES
dist/vibelet.mjs (+ dist/index.cjs, dist/web/assets/index-BiSnL70b.js)
INDICATORS (IOCs)
- ipv6: b::
- urls: https://vibelet.icu
- domains: vibelet.icu, meta.group, keyword.control.track.ng, punctuation.definition.group.no
- emails: self@wyattbaldwin.com
- payloadFileHash: 697509bb075d44f37302509721aacf0fe1323dc6260fe1dc658f7a1f02547e91
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @vibelet/cli | 1.2.154 (affected) | — |
Aliases
Browse GCVE Records
482 records in the GCVE database · Updated August 26, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.