VDB
GCVE-110-OSM-2026-10826
GCVE-110-OSM-2026-10826
Advisory PublishedCVSS 8.8/10
This package includes a 9MB file named okta-aio that is actually a bash script with a massive embedded base64 section that when decoded presents a Linux ELF binary.
Key conclusions:
- It is an authentication-portability and credential-brokering system, not demonstrably a generic malware implant.
- It intentionally makes Okta managed-device identity and FastPass/signed-nonce authentication portable.
- It explicitly uploads Codex and Aircover refresh tokens to a remote worker.
- It enrolls 1Password browser/device material and can decrypt complete vault contents, including passwords, TOTP seeds, SSH keys,
payment cards, and API credentials.
- prove 1password --with-vault-dump writes a mode-0600 cleartext vault export.
- It can fan one Okta authentication event out into credentials for numerous SaaS targets.
- Granola key generation is documented as local-only. Its JavaScript evaluation occurs inside a copied-app loopback bridge; I found
no evidence that the remote worker directly supplies those expressions.
- It can expose the trusted-machine authentication responder through a Cloudflare tunnel.
- It supports LaunchAgent or systemd-user persistence for that responder.
- It contains a command to archive the macOS System keychain and /var/db/SystemKey for offline SCEP extraction.
- No unconditional network-downloaded executable stage, blockchain activity, or general remote native-code execution channel was
found.
ADDITIONAL FINDINGS
- Brand New Package
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @postman-cse/okta-aio-linux-arm64 | all (affected) | — |
Aliases
Browse GCVE Records
417 records in the GCVE database · Updated August 26, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.