VDB
GCVE-110-OSM-2026-12123
GCVE-110-OSM-2026-12123
Advisory PublishedCVSS 9.6/10
postgreesqlhelper is a malicious npm supply-chain package that executes on root import, loads encrypted remote stages, and deploys a credential-stealing Socket.IO backdoor with attempted cross-platform persistence.
On root import, index.js decodes Base64 content concealed in parse.ts.map and init.ts.map, writes parsetmp.js and config.js, loads the first loader, and asynchronously deletes the original and dropped files. The loader decrypts a JSON sessions field using scrypt-derived AES-256-CBC material and evaluates the plaintext. The recovered bootstrap creates Programs_X64 under the OS temporary directory, writes main.js and a Windows main.vbs launcher, installs axios, node-machine-id, and socket.io-client, then starts main.js detached. The final recovered stage collects browser-extension settings, wallet data, cloud credentials, SSH material, shell histories, selected documents, Sticky Notes data, and host metadata; supports arbitrary file and directory upload, remote shell execution, directory listing, and file reads through Socket.IO; and attempts Windows Run-key, macOS LaunchAgent, and Linux XDG autostart persistence. No interactive C2 communication was performed during analysis. The macOS and Linux persistence launch arguments may be defective because they reference the script directory instead of main.js.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | postgreesqlhelper | all (affected) | — |
Aliases
Browse GCVE Records
386 records in the GCVE database · Updated September 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.