VDB
GCVE-110-OSM-2026-11139
GCVE-110-OSM-2026-11139
Advisory PublishedCVSS 8.8/10
This package is a workspace exfiltration tool disguised as a Spotify URL resolver. The OSV advisory (MAL-2026-14487) is fully corroborated by the evidence: src/config.js contains a hardcoded Telegram bot token (8837512876:AAHXFLvmJBEYmVhXgjVNgdzx8s_eilP4RsM) and chat ID, and the package description ('Automated server backup tool with Telegram delivery') exposes the true function — archiving process.cwd() and uploading it to an attacker-controlled Telegram channel on a 60-minute loop.
ENTRY
bin/cli.js (bin: ./bin/cli.js)
DESTINATION
- 1 exfil (telegram-bot)
(values recorded in verified_iocs)
ADDITIONAL FINDINGS
- Brand New Package
- Very New NPM Publisher Account
TELEGRAM THREAT-ACTOR INTELLIGENCE (live API enrichment):
Bot @tramadol19bot (id 8837512876)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | spotify-url-resolovela | all (affected) | — |
Browse GCVE Records
3,425 records in the GCVE database · Updated September 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.