VDB

GCVE-110-OSM-2026-10635

GCVE-110-OSM-2026-10635
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 7, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code. ENTRY e2ee/index.js (main: index.js) PERSISTENCE - Startup Persistence in src/api/action/changeAvatar.js: ".profile" - Startup Persistence in src/api/users/getUserInfo.js: ".profile" - Startup Persistence in src/api/users/getUserInfoV2.js: ".profile" - Startup Persistence in src/app/threadInfoRealtimeSync.js: ".profile" - Startup Persistence in src/utils/shadowx-utils.js: ".profile" - Startup Persistence in src/vendor/fca-unofficial/src/getUserInfo.js: ".profile" DESTINATION - 17 exfil (custom-c2, reconstructed) - 1 c2 (domains) - 1 fetched-payload (deobfuscated) (values recorded in verified_iocs) EXFIL - Environment Variable Exfiltration in e2ee/vendor/fb-e2ee.cjs: "process.env.FB_E2EE_MEDIA_UPLOAD_AUTH ? { host: process.env.FB_E2EE_MEDIA_UPLOAD..." - Environment Variable Exfiltration in src/api/socket/e2ee/e2ee/vendor/fb-e2ee.cjs: "process.env.FB_E2EE_MEDIA_UPLOAD_AUTH ? { host: process.env.FB_E2EE_MEDIA_UPLOAD..." - Environment Variable Exfiltration in src/api/socket/e2ee/vendor/fb-e2ee.cjs: "process.env.FB_E2EE_MEDIA_UPLOAD_AUTH ? { host: process.env.FB_E2EE_MEDIA_UPLOAD..." - Data Encoding for Exfiltration in e2ee/vendor/fb-e2ee.cjs: "Buffer.from([5]).toString("base64")" - Data Encoding for Exfiltration in src/api/action/setPostReaction.js: "Buffer.from("feedback:" + postID).toString("base64")" - Data Encoding for Exfiltration in src/api/messaging/uploadAttachment.js: "encodeURIComponent(userId" - Data Encoding for Exfiltration in src/api/socket/e2ee/e2ee/vendor/fb-e2ee.cjs: "Buffer.from([5]).toString("base64")" - Data Encoding for Exfiltration in src/api/socket/e2ee/vendor/fb-e2ee.cjs: "Buffer.from([5]).toString("base64")" (+8 more) OBFUSCATION - IOCs Found in Deobfuscated Code in e2ee/index.js - IOCs Found in Deobfuscated Code in e2ee/ratchet.js - IOCs Found in Deobfuscated Code in src/api/socket/e2ee/e2ee/ratchet.js - IOCs Found in Deobfuscated Code in src/api/socket/e2ee/ratchet.js - Dynamic Base64 Decoding in e2ee/index.js: "Buffer.from(input, "base64")" - Dynamic Base64 Decoding in e2ee/ratchet.js: "Buffer.from(v, "base64")" - Dynamic Base64 Decoding in e2ee/store.js: "Buffer.from(data, "base64")" - Dynamic Base64 Decoding in e2ee/vendor/fb-e2ee.cjs: "Buffer.from(id, "base64")" (+13 more) ADDITIONAL FINDINGS - Platform Detection with Data Collection in e2ee/protocol.js: "JSON.stringify({ type: "x3dh_init", ek: senderEphemeralPub.toS" - Dynamic Code Execution in src/api/messaging/uploadAttachment.js: "exec(s)" - Suspicious URL Pattern in Template Literal in src/api/messaging/uploadAttachment.js: "https://www.facebook.com/ajax/mercury/upload.php?${...}" PAYLOAD FILES src/api/messaging/uploadAttachment.js (+ e2ee/vendor/fb-e2ee.cjs, src/api/socket/e2ee/e2ee/vendor/fb-e2ee.cjs)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownshadowx-fcaall (affected)

References

advisory
vendor

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›