VDB

GCVE-110-OSM-2026-10626

GCVE-110-OSM-2026-10626
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 18, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code. ENTRY dist/vibelet.mjs (bin: dist/vibelet.mjs) PERSISTENCE - Startup Persistence in dist/index.cjs: ".profile" - Startup Persistence in dist/web/assets/index-BiSnL70b.js: ".profile" DESTINATION - reconstructed: https://react.dev/errors/null (primary, reconstructed) in dist/web/assets/index-BiSnL70b.js - reconstructed: https://github.com/syntax-tree/hast-util-to-jsx-runtime#cannot-parse-style-attribute (reconstructed) in dist/web/assets/index-BiSnL70b.js - custom-c2: react.dev (reconstructed) in dist/web/assets/index-BiSnL70b.js - custom-c2: github.com (reconstructed) in dist/vibelet.mjs - tunnel: https://abc.trycloudflare.com (plaintext) in dist/vibelet.mjs - custom-c2: https://exp.host/--/api/v2/push/send (plaintext) in dist/index.cjs - custom-c2: https://exp.host/--/api/v2/push/getReceipts (plaintext) in dist/index.cjs - custom-c2: https://www.cl.cam.ac.uk/%7Emgk25/ucs/utf8_check.c (plaintext) in dist/vibelet.mjs (+19 more) EXFIL - OAST/Interactsh Exfiltration in dist/index.cjs: ".trycloudflare.com" - Environment Variable Exfiltration in dist/vibelet.mjs: "process.env.VIBE_CLAUDE_DRIVER ? normalizeDriver(process.env.VIBE_CLAUDE_DRIVER)..." - OAST/Interactsh Exfiltration in dist/vibelet.mjs: ".trycloudflare.com" - Corporate Environment Targeting in dist/vibelet.mjs: "tModeForData = function getBestModeForData (dataStr) { if (Regex.test" - Corporate Environment Targeting in dist/web/assets/apache-Pmp26Uib.js: "tMod|LastModifiedFactor|MaxExpire))\\\\b"},{"captures":{"1":{"name":"keyword.cer..." - Corporate Environment Targeting in dist/web/assets/applescript-Co6uUVPk.js: "tmost|version)\\\\b","name":"support.constant.standard-suite.applescript"},{"mat..." - Corporate Environment Targeting in dist/web/assets/blade-D4QpJJKB.js: "tmore)|bson_((?:de|en)code))\\\\b","name":"support.function.mongo.php"},{"match" - Corporate Environment Targeting in dist/web/assets/emacs-lisp-C9XAeP06.js: "magenta|term-color-red|term-color-white|term-color-yellow|term-underline|term|te..." (+17 more) OBFUSCATION - Obfuscation: augmented proxied array function replacements in dist/index.cjs - Obfuscation: function to array replacements in dist/index.cjs - Dynamic Base64 Decoding in dist/web/assets/index-BiSnL70b.js: "atob(o)" - Base64 Encoded Payload in dist/index.cjs: "'laOGicaGBwv0Ag9KoIaNue9tvcCScIaGicbWyxrOoIaNl2HVB2SVy2XHDwrLl3bLCM1PC3nPB24TCMv..." - String Array Obfuscation in dist/index.cjs: "['0','1','2','3','4','5','6','7','8','9','A','B','C','D','E','F','G','H','I','J'..." - Unicode Escape Obfuscation in dist/index.cjs: "\x0a\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20" - String Array Obfuscation in dist/vibelet.mjs: "[ '0', '1', '2', '3', '4', '5', '6', '7', '8', '9', 'A', 'B', 'C', 'D', 'E', 'F'..." - String Array Obfuscation in dist/web/assets/asciidoc-Ve4PFQV2.js: "["html","yaml","csv","css","ini","java","lua","make","perl","r","ruby","php","sq..." (+28 more) ADDITIONAL FINDINGS - Download Execute Delete Pattern in dist/web/assets/blade-D4QpJJKB.js: "executable|link|readable|writ(e)?able)|disk_(free|total)_space|diskfreespace|dir..." - Reconstructed Obfuscated URL in dist/web/assets/index-BiSnL70b.js: "https://react.dev/errors/null" - Indirect Function Constructor Access in dist/index.cjs: "['constructor']" - Dynamic Code Execution in dist/vibelet.mjs: "exec(str)" - Silent Process Execution in dist/vibelet.mjs: "stdio: 'ignore'" - Suspicious TLD Domain in dist/vibelet.mjs: "https://www.cl.cam" (+1 more) PAYLOAD FILES dist/vibelet.mjs (+ dist/index.cjs, dist/web/assets/index-BiSnL70b.js) INDICATORS (IOCs) - ipv6: b:: - urls: https://vibelet.icu - domains: vibelet.icu, meta.group, keyword.control.track.ng, punctuation.definition.group.no - emails: self@wyattbaldwin.com - payloadFileHash: 697509bb075d44f37302509721aacf0fe1323dc6260fe1dc658f7a1f02547e91

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@vibelet/cli1.2.154 (affected)

References

advisory
vendor

Browse GCVE Records

482 records in the GCVE database · Updated August 26, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›