VDB
GCVE-110-OSM-2026-12266
GCVE-110-OSM-2026-12266
Advisory PublishedCVSS 8.8/10
The package ships console.js, which when loaded in a browser on any host matching duel.com fetches https://unpkg.com/x6842179305@1.0.3/1.js and https://unpkg.com/x6842179305@1.0.3/ui.js and executes both via (0, eval)(...). On other hosts it redirects the page to duel.com. The declared main/unpkg entry 1.js is a ~740KB single-line Function("ZU7mhwD", "...") loader built from hex-escaped char arrays and a rotor-style decoder, with no readable source. Package metadata is placeholder-quality (name xa424234657567, no README, no repository), inconsistent with a library and consistent with a payload-delivery artifact. Consuming this package on a page served under duel.com results in remote, mutable, attacker-controlled code executing in the page context.
ENTRY
1.js (main: 1.js)
DESTINATION
- 2 c2 (urls, domains)
(values recorded in verified_iocs)
OBFUSCATION
- Obfuscation (osm-deobfuscator): unknown in ui.js
- Obfuscation patterns: unicodeHeavy, hexHeavy in 1.js
ADDITIONAL FINDINGS
- Very New NPM Publisher Account
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | xa424234657567 | all (affected) | — |
Aliases
Browse GCVE Records
374 records in the GCVE database · Updated September 19, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.