VDB
GCVE-110-OSM-2026-11715
GCVE-110-OSM-2026-11715
Advisory PublishedCVSS 9.6/10
This legitimate package was compromised today by a threat actor who appears to have included a Shai-hulud v1 payload in the index.js file.
ENTRY
bin/run.js (bin: bin/run.js)
- Preinstall Script in package.json: ""preinstall": "bun run index.js""
- Postinstall Script in package.json: ""postinstall": "node -e \""
PERSISTENCE
- Startup Persistence in dist/commands/citty/config.js: ".profile"
- Startup Persistence in dist/lib/config.js: ".profile"
DESTINATION
- 8 exfil (custom-c2)
(values recorded in verified_iocs)
EXFIL
- Environment Variable Exfiltration in dist/cli.js: "process.env.BLUEAI_CONFIG_DIR ?? defaultConfigDir(); const specSources = await f..."
- Environment Variable Exfiltration in dist/commands/citty/doctor.js: "process.env.BLUEAI_PROBE_GATEWAY ?? 'https://bmc-model-openapi.bluemediagroup.cn..."
- Environment Variable Exfiltration in dist/lib/executor.js: "process.env[envGatewayKey] ?? service.gateway; const headerProvider = authRequir..."
- Sensitive File Access in dist/lib/validation.js: "'/.npmrc'"
- Environment Variable Exfiltration in index.js: "process.env,_0x40cf8c=await fetch"
- Data Encoding for Exfiltration in dist/commands/citty/task-status.js: "encodeURIComponent(entry.statusQueryParam)}=${encodeURIComponent(taskId"
- Data Encoding for Exfiltration in dist/lib/executor.js: "encodeURIComponent(k)}=${encodeURIComponent(String(v"
- Data Encoding for Exfiltration in dist/lib/pagination.js: "encodeURIComponent(k)}=${encodeURIComponent(String(v"
(+5 more)
OBFUSCATION
- Obfuscation: augmented proxied array function replacements in index.js
- Base64 Encoded Payload in index.js: "'ufzis2eZzdrjwM05tge0wNfvtLjlsNDzovzJDw5hze1ACKG2mduRvtHbqM5pCLrwDwzKwLvUu3O4twW..."
- String Array Obfuscation in index.js: "_0x429148[_0x256a2b-0x1]"
- Obfuscation patterns: hexVariables, hexHeavy in index.js
ADDITIONAL FINDINGS
- Download Execute Delete Pattern in dist/lib/task-registry.js: "exec(content2.trim()); if (!m2) { unlink"
- Campaign marker: PolinRider in openapi/merged/minimaxi.yaml: "ss_info"
- Dynamic Code Execution in dist/lib/materialize.js: "exec(raw)"
- Malicious Dependency Detected in package.json
PAYLOAD FILES
index.js (+ dist/lib/validation.js, dist/lib/executor.js)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | blueai-cli | 0.7.0 (affected) | — |
Browse GCVE Records
540 records in the GCVE database · Updated September 8, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.