VDB
GCVE-110-OSM-2026-1254
GCVE-110-OSM-2026-1254
Advisory PublishedCVSS 9.6/10
Exfiltrates system info, .env files, shell history, credential documents, and Telegram Desktop session data to changelog.rest via HTTP POST on require() and postinstall. On Linux, injects attacker SSH public key into ~/.ssh/authorized_keys. Byte-for-byte identical payload to terminal-pretty-logger by same publisher (vichevmafaaxe@hotmail.com).
dist/logger.js (SHA256: 2414cab6...) is identical to terminal-pretty-logger. Same execution chain: _ssi, _spe, _sejf, _saf, _stia. Same C2 at changelog.rest. Same SSH key injection on Linux.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | cli-pretty-logger | 1.0.0 (affected) | — |
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.