VDB

GCVE-110-OSM-2026-1203

GCVE-110-OSM-2026-1203
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published April 1, 2026
On require(), lib/caller.js fetches from http://server-check-genimi.vercel.app/defy/v3 (0/94 VT — evasion working) and executes the stage-2 payload on HTTP 404 response via new Function.constructor('require', payload)(require). 404-triggered delivery deliberately evades sandboxes that receive a benign 200. The campaign operator's stage-2 payload was decoded (same operator u_k=301, t=3; npoint.io C2 variant; SHA256 of extracted JS: fdb582f16475cb79bebd0dffc48d610430cae2e39e9a3e2abd373b3413691838) and is a cross-platform RAT and infostealer: steals browser credentials and crypto wallet data from 13 Chromium-based browsers, exfiltrates .env files and the full home directory to http://144.172.110.132:8086/upload (Vultr VPS), and establishes a socket.io reverse shell at ws://144.172.110.132:8087 with clipboard monitoring. Sibling chai-extensions-extras@1.2.5 carries an identical loader. lib/caller.js IIFE assembles C2 URL from lib/config.js (split to defeat IOC matching). GETs http://server-check-genimi.vercel.app/defy/v3 with bearrtoken:logo. On 200: logs decoy and exits cleanly (sandbox/scanner evasion — 0/94 VT detections on URL). On 404: executes error.response.data.token via new (Function.constructor)('require', res.token)(require). The stage-2 payload from this C2 was not independently decoded; the campaign operator's npoint.io payload (identical loader pattern, same response.data.cookie field, operator u_k=301 t=3) was decoded via synchrony. Hash correction: 00a32991... was SHA256 of the raw JSON HTTP response wrapper; correct extracted-JS hash is fdb582f1... — not in VT. Payload behavior: (1) ldbScript — browser credential stealer targeting 13 Chromium-based browsers, 40 crypto wallet extensions (MetaMask, Phantom, etc.), macOS login.keychain-db; uploads to http://144.172.110.132:8086/upload. (2) autoUploadScript — full filesystem crawler targeting .env* files; uploads ≤10MB files. (3) socketScript — socket.io RAT at ws://144.172.110.132:8087 with remote shell and 1-second clipboard monitoring. C2: Vultr VPS, hostname gifted-rhodes.144-172-110-132.plesk.page, 0/94 VT detections. Operator: u_k=301, t=3, HMAC SuperStr0ngSecret@)@^.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownexpress-flowlimit

References

vendor

Browse GCVE Records

75,045 records in the GCVE database · Updated July 28, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›