VDB
GCVE-110-OSM-2026-10635
GCVE-110-OSM-2026-10635
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code.
ENTRY
e2ee/index.js (main: index.js)
PERSISTENCE
- Startup Persistence in src/api/action/changeAvatar.js: ".profile"
- Startup Persistence in src/api/users/getUserInfo.js: ".profile"
- Startup Persistence in src/api/users/getUserInfoV2.js: ".profile"
- Startup Persistence in src/app/threadInfoRealtimeSync.js: ".profile"
- Startup Persistence in src/utils/shadowx-utils.js: ".profile"
- Startup Persistence in src/vendor/fca-unofficial/src/getUserInfo.js: ".profile"
DESTINATION
- 17 exfil (custom-c2, reconstructed)
- 1 c2 (domains)
- 1 fetched-payload (deobfuscated)
(values recorded in verified_iocs)
EXFIL
- Environment Variable Exfiltration in e2ee/vendor/fb-e2ee.cjs: "process.env.FB_E2EE_MEDIA_UPLOAD_AUTH ? { host: process.env.FB_E2EE_MEDIA_UPLOAD..."
- Environment Variable Exfiltration in src/api/socket/e2ee/e2ee/vendor/fb-e2ee.cjs: "process.env.FB_E2EE_MEDIA_UPLOAD_AUTH ? { host: process.env.FB_E2EE_MEDIA_UPLOAD..."
- Environment Variable Exfiltration in src/api/socket/e2ee/vendor/fb-e2ee.cjs: "process.env.FB_E2EE_MEDIA_UPLOAD_AUTH ? { host: process.env.FB_E2EE_MEDIA_UPLOAD..."
- Data Encoding for Exfiltration in e2ee/vendor/fb-e2ee.cjs: "Buffer.from([5]).toString("base64")"
- Data Encoding for Exfiltration in src/api/action/setPostReaction.js: "Buffer.from("feedback:" + postID).toString("base64")"
- Data Encoding for Exfiltration in src/api/messaging/uploadAttachment.js: "encodeURIComponent(userId"
- Data Encoding for Exfiltration in src/api/socket/e2ee/e2ee/vendor/fb-e2ee.cjs: "Buffer.from([5]).toString("base64")"
- Data Encoding for Exfiltration in src/api/socket/e2ee/vendor/fb-e2ee.cjs: "Buffer.from([5]).toString("base64")"
(+8 more)
OBFUSCATION
- IOCs Found in Deobfuscated Code in e2ee/index.js
- IOCs Found in Deobfuscated Code in e2ee/ratchet.js
- IOCs Found in Deobfuscated Code in src/api/socket/e2ee/e2ee/ratchet.js
- IOCs Found in Deobfuscated Code in src/api/socket/e2ee/ratchet.js
- Dynamic Base64 Decoding in e2ee/index.js: "Buffer.from(input, "base64")"
- Dynamic Base64 Decoding in e2ee/ratchet.js: "Buffer.from(v, "base64")"
- Dynamic Base64 Decoding in e2ee/store.js: "Buffer.from(data, "base64")"
- Dynamic Base64 Decoding in e2ee/vendor/fb-e2ee.cjs: "Buffer.from(id, "base64")"
(+13 more)
ADDITIONAL FINDINGS
- Platform Detection with Data Collection in e2ee/protocol.js: "JSON.stringify({ type: "x3dh_init", ek: senderEphemeralPub.toS"
- Dynamic Code Execution in src/api/messaging/uploadAttachment.js: "exec(s)"
- Suspicious URL Pattern in Template Literal in src/api/messaging/uploadAttachment.js: "https://www.facebook.com/ajax/mercury/upload.php?${...}"
PAYLOAD FILES
src/api/messaging/uploadAttachment.js (+ e2ee/vendor/fb-e2ee.cjs, src/api/socket/e2ee/e2ee/vendor/fb-e2ee.cjs)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | shadowx-fca | all (affected) | — |
Aliases
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.