VDB

GCVE-110-OSM-2026-10864

GCVE-110-OSM-2026-10864
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published August 21, 2026
This package is a heavily obfuscated WhatsApp bot with attacker-controlled C2 infrastructure masquerading as a 'network socket engine'. The Contagious Interview 2026 campaign marker `_0x1c18` (Famous Chollima/UNC5267, DPRK) is present in multiple files. Deobfuscation recovered 55 IOCs across 10+ files, including hardcoded endpoints like `ranux-api-2-365c9689faa0.herokuapp.com`, `sublk-api.vercel.app`, and `api.zanta-mini.store` — all attacker-controlled infrastructure hidden inside obfuscator.io string arrays. The OSV advisory corroborates the WhatsApp session hijacking model: `tenantManager.js` (~134KB obfuscated) orchestrates multi-tenant control, `plugins/pair.js` handles WA session pairing, and the `@whiskeysockets/baileys` dependency is redirected to an unversioned personal GitHub fork (`github:rcedubot/X`), meaning every install pulls attacker-mutable code at load time. The combination of whole-package obfuscation, confirmed DPRK campaign markers, recovered C2 domains, deceptive package description, and mutable supply-chain dependency override presents an unambiguous attacker model: persistent WhatsApp session takeover with exfiltration to attacker-controlled endpoints. ENTRY index.js (main: index.js) DESTINATION - 19 fetched-payload (deobfuscated) (values recorded in verified_iocs) EXFIL - Corporate Environment Targeting in plugins/fitgirl.js: "tmO']+this['kARjAN']),_0x3e8e0b=_0xa16e99['test" - System Information Exfiltration in plugins/ai.js: "__filename=fileURLToPath(import.meta.url),__dirname=_0x554c92[_0x2c4337(0x1cc,0x..." - System Information Exfiltration in plugins/apk.js: "__dirname=_0x58bee2[_0x119181(0x582,0x4e8,0x4e6,0x47a)](__filename),_0x180e59={}..." - System Information Exfiltration in plugins/creater.js: "__filename=fileURLToPath(import.meta.url),__dirname=_0x1bf0be[_0x4a9b9d('259v',0..." - System Information Exfiltration in plugins/csong.js: "__dirname=_0x31ad97[_0x3cb367(0x9c,-0x6e,')LoG',-0x137)](__filename),_0x2007fd={..." - System Information Exfiltration in plugins/movie.js: "__dirname=_0x1cba7c[_0x546dee(0x60c,0x2a2,'kZ$q',0x26a)](__filename),_0x501b9b={..." - System Information Exfiltration in plugins/settings.js: "__filename=fileURLToPath(import.meta.url),__dirname=_0x3d060b[_0x51b2ed(0x77f,0x..." OBFUSCATION - IOCs Found in Deobfuscated Code in config.js - IOCs Found in Deobfuscated Code in database.js - IOCs Found in Deobfuscated Code in plugins/ai.js - IOCs Found in Deobfuscated Code in plugins/antidelete.js - IOCs Found in Deobfuscated Code in plugins/creater.js - IOCs Found in Deobfuscated Code in plugins/csong.js - IOCs Found in Deobfuscated Code in plugins/menu.js - IOCs Found in Deobfuscated Code in plugins/pair.js (+267 more) ADDITIONAL FINDINGS - Campaign marker: Contagious Interview 2026 in plugins/group.js: "_0x1c18" - Very New NPM Publisher Account - Campaign marker: Contagious Interview Malicious Dictionary in database.js: "_0x28aa" - Malicious Dependency Detected in package.json PAYLOAD FILES plugins/ai.js (+ plugins/creater.js, plugins/csong.js)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownranux-proall (affected)

References

advisory
vendor

Browse GCVE Records

3,528 records in the GCVE database · Updated September 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›