VDB

GCVE-110-OSM-2026-11139

GCVE-110-OSM-2026-11139
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published August 25, 2026
This package is a workspace exfiltration tool disguised as a Spotify URL resolver. The OSV advisory (MAL-2026-14487) is fully corroborated by the evidence: src/config.js contains a hardcoded Telegram bot token (8837512876:AAHXFLvmJBEYmVhXgjVNgdzx8s_eilP4RsM) and chat ID, and the package description ('Automated server backup tool with Telegram delivery') exposes the true function — archiving process.cwd() and uploading it to an attacker-controlled Telegram channel on a 60-minute loop. ENTRY bin/cli.js (bin: ./bin/cli.js) DESTINATION - 1 exfil (telegram-bot) (values recorded in verified_iocs) ADDITIONAL FINDINGS - Brand New Package - Very New NPM Publisher Account TELEGRAM THREAT-ACTOR INTELLIGENCE (live API enrichment): Bot @tramadol19bot (id 8837512876)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownspotify-url-resolovelaall (affected)

Browse GCVE Records

3,425 records in the GCVE database · Updated September 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›