VDB

GCVE-110-OSM-2026-12266

GCVE-110-OSM-2026-12266
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published September 18, 2026
The package ships console.js, which when loaded in a browser on any host matching duel.com fetches https://unpkg.com/x6842179305@1.0.3/1.js and https://unpkg.com/x6842179305@1.0.3/ui.js and executes both via (0, eval)(...). On other hosts it redirects the page to duel.com. The declared main/unpkg entry 1.js is a ~740KB single-line Function("ZU7mhwD", "...") loader built from hex-escaped char arrays and a rotor-style decoder, with no readable source. Package metadata is placeholder-quality (name xa424234657567, no README, no repository), inconsistent with a library and consistent with a payload-delivery artifact. Consuming this package on a page served under duel.com results in remote, mutable, attacker-controlled code executing in the page context. ENTRY 1.js (main: 1.js) DESTINATION - 2 c2 (urls, domains) (values recorded in verified_iocs) OBFUSCATION - Obfuscation (osm-deobfuscator): unknown in ui.js - Obfuscation patterns: unicodeHeavy, hexHeavy in 1.js ADDITIONAL FINDINGS - Very New NPM Publisher Account

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownxa424234657567all (affected)

References

advisory
vendor

Browse GCVE Records

374 records in the GCVE database · Updated September 19, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›