VDB

GCVE-110-OSM-2026-12673

GCVE-110-OSM-2026-12673
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 7, 2026
This package masquerades as a React Native BLE SDK but contains a fully-functional device fingerprinting and exfiltration payload. The entrypoint code in dist/index.js explicitly collects GPS coordinates (latitude/longitude via expo-location), device identifiers (uniqueId, deviceName, IP address), root/emulator status, battery state, and network type, then queues all of it for transmission via a rotating pool of three hardcoded Telegram bot tokens. The attacker model is mobile-device surveillance: the SDK is designed to be embedded in React Native apps, giving the attacker access to the end-user's physical location, device fingerprint, and security posture via api.telegram.org. Deobfuscation of dist/index.mjs and dist/src/update.mjs recovered these same IOCs from obfuscated code, confirming deliberate concealment. The Telegram bot handles correspond to @skobo2_bot, @otp_liv_skoegle_bot, and @skologs_bot — consistent with the publisher's other package names (haversine-skoegle, mb64-vpn-detect) suggesting a sustained campaign. ENTRY dist/index.js (main: dist/index.js) DESTINATION - 7 exfil (telegram-bot, reconstructed) - 1 c2 (domains) (values recorded in verified_iocs) EXFIL - Data Encoding for Exfiltration in dist/index.mjs: "btoa(" - Data Encoding for Exfiltration in dist/src/BLEService.mjs: "btoa(" - Data Encoding for Exfiltration in dist/src/bgn.mjs: "btoa(" - Data Encoding for Exfiltration in dist/src/ble.mjs: "btoa(" - Data Encoding for Exfiltration in dist/src/update.mjs: "btoa(" OBFUSCATION - IOCs Found in Deobfuscated Code in dist/index.mjs - IOCs Found in Deobfuscated Code in dist/src/update.mjs - Dynamic Base64 Decoding in dist/index.mjs: "atob(characteristic." - Dynamic Base64 Decoding in dist/src/BLEService.mjs: "atob(characteristic." - Dynamic Base64 Decoding in dist/src/bgn.mjs: "atob(characteristic." - Dynamic Base64 Decoding in dist/src/ble.mjs: "atob(characteristic." - Dynamic Base64 Decoding in dist/src/update.mjs: "atob(characteristic." - Strings Extracted from Deobfuscated Code in dist/src/BLEService.mjs (+3 more) ADDITIONAL FINDINGS - Reconstructed Obfuscated URL in dist/index.js: "https://www.google.com/maps?q=null,null" - Suspicious URL Pattern in Template Literal in dist/index.js: "https://api.telegram.org/bot${...}/sendMessage" PAYLOAD FILES dist/index.mjs (+ dist/src/update.mjs)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownblekitall (affected)—

References

advisory
vendor

Browse GCVE Records

3,164 records in the GCVE database · Updated October 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›