VDB
GCVE-110-OSM-2026-10629
GCVE-110-OSM-2026-10629
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution, network activity, obfuscated code.
ENTRY
index.js (main: index.js)
DESTINATION
- custom-c2: https://jsonkeeper.com/b/XRGF3 (primary, decoded) in lib/caller.js
- custom-c2: https://jsonkeeper.com/b/4NAKK (decoded) in lib/caller.js
- custom-c2: jsonkeeper.com (decoded) in lib/caller.js
- custom-c2: https://json.extendsclass.com/bin/26d6d7d075e1 (plaintext) in lib/caller.js
- custom-c2: json.extendsclass.com (plaintext) in lib/caller.js
EXFIL
- Fetch and Eval/Exec in lib/caller.js: "axios.get(src, { headers: { [k]: v } })).data.cookie; const handler = new Functi..."
- Payload Download from Paste Service in lib/caller.js: "json.extendsclass.com"
- Network Request in lib/caller.js: "axios.get("
OBFUSCATION
- Global Variable Shadowing in lib/caller.js: "const process = {"
- Decoded Base64 Content in lib/caller.js
- Decoded Base64 Content in lib/const.js
- Deobfuscation Failed in lib/caller.js
- recovered 2 urls, 1 domains from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Stealth Background Process Spawning in index.js: "spawn("node", [script, JSON.stringify(args)], { detached: true, stdio: "ignore" ..."
- Shell Command Execution in index.js: "require("child_process")"
- Silent Process Execution in index.js: "stdio: "ignore""
- Detached Child Process Payload in index.js: "spawn("node", [script, JSON.stringify(args)], { detached: true"
- Dynamic Code Execution in lib/caller.js: "Function.constructor("
PAYLOAD FILES
lib/caller.js
INDICATORS (IOCs)
- urls: http://192.168.1.42:9200
- payloadFileHash: cfb5d9e644285bd872d3fa1921a279a29e2b0b47beaa5fe746c60287aa9e084f
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | type-plint | all (affected) | — |
Aliases
Browse GCVE Records
3,587 records in the GCVE database · Updated September 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.