VDB

GCVE-110-OSM-2026-10989

GCVE-110-OSM-2026-10989
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 26, 2026
Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it. Judge assessment: This is consistent with a credential-stealing and persistence-capable loader installed by an attacker to compromise npm users who import the package. The entrypoint `dist/index.mjs` verifies and then spawns `dist/internal/calc-eng.dat` as a detached child process, while the recovered payload in that file includes browser login harvesting (`firefox/*/logins.json`, Brave/Edge login paths), cron and `.bashrc` persistence, and C2/exfil targets such as `217.60.77.63` and `https://litterbox.catbox.moe/resources/internals/api.php`. The `chai-max-browser-theft` signature, `browser-data-theft`, and `cron-persistence` findings align with the plaintext IOC recovery, so this is not just a heuristic miss but a real malware payload. The package’s brand-new publisher account and no-repository metadata reinforce the attacker model of a fresh supply-chain implant. ENTRY dist/index.mjs (main: ./dist/index.mjs) LOOT - Browser Data Theft in dist/internal/calc-eng.dat: "firefox/*/logins.json; do [ -f "$p" ] || continue; PR=$(basename $(dirname "$p")..." PERSISTENCE - Cron Job Persistence in dist/internal/calc-eng.dat: "crontab -" - Startup Persistence in dist/internal/calc-eng.dat: ".bashrc" DESTINATION - 6 c2 (ipv4, urls, domains) (values recorded in verified_iocs) ADDITIONAL FINDINGS - Chai-Max Browser Data Theft in dist/internal/calc-eng.dat: "BraveSoftware/Brave-Browser microsoft-edge; do for p in ~/.config/$b/*/Login" - Detached Child Process Payload in dist/index.mjs: "spawn(binaryPath, [], { stdio: 'pipe', shell: false, detached: true" - Brand New Package - Very New NPM Publisher Account PAYLOAD FILES dist/internal/calc-eng.dat

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownhydration-ui-clsall (affected)

References

advisory
vendor

Browse GCVE Records

3,521 records in the GCVE database · Updated September 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›