VDB

GCVE-110-OSM-2026-1254

GCVE-110-OSM-2026-1254
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published April 1, 2026
Exfiltrates system info, .env files, shell history, credential documents, and Telegram Desktop session data to changelog.rest via HTTP POST on require() and postinstall. On Linux, injects attacker SSH public key into ~/.ssh/authorized_keys. Byte-for-byte identical payload to terminal-pretty-logger by same publisher (vichevmafaaxe@hotmail.com). dist/logger.js (SHA256: 2414cab6...) is identical to terminal-pretty-logger. Same execution chain: _ssi, _spe, _sejf, _saf, _stia. Same C2 at changelog.rest. Same SSH key injection on Linux.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowncli-pretty-logger1.0.0 (affected)

References

vendor

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›