VDB
GCVE-110-OSM-2026-11249
GCVE-110-OSM-2026-11249
Advisory PublishedCVSS 9.6/10
Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Judge assessment: This package matches an attacker-controlled loader pattern: the entrypoint `index.js` is a base64-encoded blob that decodes to multiple hardcoded external URLs and tokens, which is far beyond normal package behavior. The recovered IOCs include six suspicious domains (`apial.yrcmza.com`, `apial.qaffvz.com`, `apial.bengvet.com`, `api-al.wentian510.com`, `api.dq87774.com`, `apial.wentian510.com`) embedded directly in the payload, indicating hidden command-and-control or exfil infrastructure. The metadata also looks like a disguised security-holding package (`description: security holding package`, `hasSecurityHolding: true`) published by `npm-support`, which is consistent with a compromised or maliciously seeded package rather than legitimate utility code. The attacker model here is a supply-chain implant intended to quietly execute hidden network interactions from consumers' machines, and the OSV advisory `MAL-2026-14571` is corroborated by the actual decoded content.
ENTRY
index.js (default-index: index.js)
OBFUSCATION
- Decoded Base64 Content in index.js
- recovered 6 urls, 6 domains from decoded/deobfuscated content
PAYLOAD FILES
index.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @hd-team/app-dnpkg-prod | all (affected) | — |
Aliases
Browse GCVE Records
825 records in the GCVE database · Updated September 1, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.