VDB
GCVE-110-OSM-2026-10864
GCVE-110-OSM-2026-10864
Advisory PublishedCVSS 8.8/10
This package is a heavily obfuscated WhatsApp bot with attacker-controlled C2 infrastructure masquerading as a 'network socket engine'. The Contagious Interview 2026 campaign marker `_0x1c18` (Famous Chollima/UNC5267, DPRK) is present in multiple files. Deobfuscation recovered 55 IOCs across 10+ files, including hardcoded endpoints like `ranux-api-2-365c9689faa0.herokuapp.com`, `sublk-api.vercel.app`, and `api.zanta-mini.store` — all attacker-controlled infrastructure hidden inside obfuscator.io string arrays. The OSV advisory corroborates the WhatsApp session hijacking model: `tenantManager.js` (~134KB obfuscated) orchestrates multi-tenant control, `plugins/pair.js` handles WA session pairing, and the `@whiskeysockets/baileys` dependency is redirected to an unversioned personal GitHub fork (`github:rcedubot/X`), meaning every install pulls attacker-mutable code at load time. The combination of whole-package obfuscation, confirmed DPRK campaign markers, recovered C2 domains, deceptive package description, and mutable supply-chain dependency override presents an unambiguous attacker model: persistent WhatsApp session takeover with exfiltration to attacker-controlled endpoints.
ENTRY
index.js (main: index.js)
DESTINATION
- 19 fetched-payload (deobfuscated)
(values recorded in verified_iocs)
EXFIL
- Corporate Environment Targeting in plugins/fitgirl.js: "tmO']+this['kARjAN']),_0x3e8e0b=_0xa16e99['test"
- System Information Exfiltration in plugins/ai.js: "__filename=fileURLToPath(import.meta.url),__dirname=_0x554c92[_0x2c4337(0x1cc,0x..."
- System Information Exfiltration in plugins/apk.js: "__dirname=_0x58bee2[_0x119181(0x582,0x4e8,0x4e6,0x47a)](__filename),_0x180e59={}..."
- System Information Exfiltration in plugins/creater.js: "__filename=fileURLToPath(import.meta.url),__dirname=_0x1bf0be[_0x4a9b9d('259v',0..."
- System Information Exfiltration in plugins/csong.js: "__dirname=_0x31ad97[_0x3cb367(0x9c,-0x6e,')LoG',-0x137)](__filename),_0x2007fd={..."
- System Information Exfiltration in plugins/movie.js: "__dirname=_0x1cba7c[_0x546dee(0x60c,0x2a2,'kZ$q',0x26a)](__filename),_0x501b9b={..."
- System Information Exfiltration in plugins/settings.js: "__filename=fileURLToPath(import.meta.url),__dirname=_0x3d060b[_0x51b2ed(0x77f,0x..."
OBFUSCATION
- IOCs Found in Deobfuscated Code in config.js
- IOCs Found in Deobfuscated Code in database.js
- IOCs Found in Deobfuscated Code in plugins/ai.js
- IOCs Found in Deobfuscated Code in plugins/antidelete.js
- IOCs Found in Deobfuscated Code in plugins/creater.js
- IOCs Found in Deobfuscated Code in plugins/csong.js
- IOCs Found in Deobfuscated Code in plugins/menu.js
- IOCs Found in Deobfuscated Code in plugins/pair.js
(+267 more)
ADDITIONAL FINDINGS
- Campaign marker: Contagious Interview 2026 in plugins/group.js: "_0x1c18"
- Very New NPM Publisher Account
- Campaign marker: Contagious Interview Malicious Dictionary in database.js: "_0x28aa"
- Malicious Dependency Detected in package.json
PAYLOAD FILES
plugins/ai.js (+ plugins/creater.js, plugins/csong.js)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | ranux-pro | all (affected) | — |
Aliases
Browse GCVE Records
3,528 records in the GCVE database · Updated September 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.