VDB
GCVE-110-OSM-2026-10631
GCVE-110-OSM-2026-10631
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code.
ENTRY
index.js (main: index.js)
LOOT
- Discord Token Theft in index.js: "dQw4w9WgXcQ"
DESTINATION
- discord-webhook: https://discord.com/api/webhooks/1527457949872685086/4Lc-4B-Yj9X64H8mWuQkiB5Bd-ZRgqUoNNWj0NMzvCJtCqBhTOZJPPGdog3HkW-L-Bh4 (primary, plaintext) in index.js
- custom-c2: twitch.tv (plaintext) in index.js
- custom-c2: epicgames.com (plaintext) in index.js
- custom-c2: steampowered.com (plaintext) in index.js
- custom-c2: steamcommunity.com (plaintext) in index.js
- custom-c2: paypal.com (plaintext) in index.js
- custom-c2: binance.com (plaintext) in index.js
- custom-c2: coinbase.com (plaintext) in index.js
(+15 more)
EXFIL
- Webhook Data Exfiltration in index.js: "discord.com/api/webhooks/1527457949872685086/4Lc-4B-Yj9X64H8mWuQkiB5Bd-ZRgqUoNNW..."
OBFUSCATION
- Decoded Hex String Content in index.js
- Base64 Encoded Payload in index.js: "'VlYme8cCAAwIDFNJTEVOVAgOcHJvY2VzcwgMc3Rkb3V0CAp3cml0ZQgCCgQBIggGAAABAIACAIQCAPw..."
- String Array Obfuscation in index.js: "['.roblox.com','roblox.com','.discord.com','discord.com','.twitter.com','.x.com'..."
- Obfuscation patterns: hexHeavy in index.js
ADDITIONAL FINDINGS
- Shell Command Execution in index.js: "require('child_process')"
- Indirect Function Constructor Access in index.js: "['constructor']"
PAYLOAD FILES
index.js
INDICATORS (IOCs)
- payloadFileHash: 5ece63a1a82ed94b0691ab3ede3e63a96fd018a72b8220aa3243da01b233bfb2
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | tilaver-mfa | all (affected) | — |
Aliases
Browse GCVE Records
867 records in the GCVE database · Updated September 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.