VDB
GCVE-110-OSM-2026-10628
GCVE-110-OSM-2026-10628
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, obfuscated code.
Entrypoint: lib/index.js (main: ./lib/index.js)
Exfil: https://raw.githubusercontent.com/Fhkryy/Fhkry/refs/heads/main/IDCHANNEL.json (custom-c2, recovery: decoded in lib/Utils/messages-media.js)
Payload: lib/Utils/messages-media.js
Secondary files: lib/Socket/socket.js, lib/Socket/socket.js.bak
Key findings:
- Decoded Base64 Content in lib/Utils/messages-media.js
- Startup Persistence in WAProto/index.js: ".profile"
- Dynamic Base64 Decoding in lib/Socket/dugong.js: "Buffer.from(jpegThumbnail, "base64")"
- Startup Persistence in lib/Socket/messages-send.js: ".profile"
- Data Encoding for Exfiltration in lib/Socket/socket.js: "Buffer.from(creds.noiseKey.public).toString("base64")"
IOCs:
- ipv4: 131.0.0.0
- urls: https://camo.githubusercontent.com/c1f3b7dcf8145e1a0d91e90aae2b7080e761e88b7d770e0e8429c369d7311425/68747470733a2f2f66696c65732e636174626f782e6d6f652f6335733967302e6a7067, https://mmg.whatsapp.net/, https://raw.githubusercontent.com/Fhkryy/Fhkry/refs/heads/main/IDCHANNEL.json
- domains: camo.githubusercontent.com, MediaDetailsMetadata.prototype.id, Conversation.prototype.id, HydratedQuickReplyButton.prototype.id, KeyExchangeMessage.prototype.id (+16 more)
- emails: 16505361212@c.us, 13135550002@c.us, server@c.us, 0@c.us
- bitcoinAddresses: 123456789ABCDEFGHJKLMNPQRSTVWXYZ
- sha256Hashes: c1f3b7dcf8145e1a0d91e90aae2b7080e761e88b7d770e0e8429c369d7311425
- payloadFileHash: bf7b2cde363fd9995c875efe18c93708460bf7eb406469191c8c1f110c0f0a05
Decoded/deobfuscated IOCs:
- urls: https://raw.githubusercontent.com/Fhkryy/Fhkry/refs/heads/main/IDCHANNEL.json
- domains: raw.githubusercontent.com
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @fhkry/baileys | 8.0.13 (affected) | — |
Aliases
Browse GCVE Records
69,226 records in the GCVE database · Updated August 24, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.