VDB
GCVE-110-OSM-2026-12673
GCVE-110-OSM-2026-12673
Advisory PublishedCVSS 9.6/10
This package masquerades as a React Native BLE SDK but contains a fully-functional device fingerprinting and exfiltration payload. The entrypoint code in dist/index.js explicitly collects GPS coordinates (latitude/longitude via expo-location), device identifiers (uniqueId, deviceName, IP address), root/emulator status, battery state, and network type, then queues all of it for transmission via a rotating pool of three hardcoded Telegram bot tokens. The attacker model is mobile-device surveillance: the SDK is designed to be embedded in React Native apps, giving the attacker access to the end-user's physical location, device fingerprint, and security posture via api.telegram.org. Deobfuscation of dist/index.mjs and dist/src/update.mjs recovered these same IOCs from obfuscated code, confirming deliberate concealment. The Telegram bot handles correspond to @skobo2_bot, @otp_liv_skoegle_bot, and @skologs_bot — consistent with the publisher's other package names (haversine-skoegle, mb64-vpn-detect) suggesting a sustained campaign.
ENTRY
dist/index.js (main: dist/index.js)
DESTINATION
- 7 exfil (telegram-bot, reconstructed)
- 1 c2 (domains)
(values recorded in verified_iocs)
EXFIL
- Data Encoding for Exfiltration in dist/index.mjs: "btoa("
- Data Encoding for Exfiltration in dist/src/BLEService.mjs: "btoa("
- Data Encoding for Exfiltration in dist/src/bgn.mjs: "btoa("
- Data Encoding for Exfiltration in dist/src/ble.mjs: "btoa("
- Data Encoding for Exfiltration in dist/src/update.mjs: "btoa("
OBFUSCATION
- IOCs Found in Deobfuscated Code in dist/index.mjs
- IOCs Found in Deobfuscated Code in dist/src/update.mjs
- Dynamic Base64 Decoding in dist/index.mjs: "atob(characteristic."
- Dynamic Base64 Decoding in dist/src/BLEService.mjs: "atob(characteristic."
- Dynamic Base64 Decoding in dist/src/bgn.mjs: "atob(characteristic."
- Dynamic Base64 Decoding in dist/src/ble.mjs: "atob(characteristic."
- Dynamic Base64 Decoding in dist/src/update.mjs: "atob(characteristic."
- Strings Extracted from Deobfuscated Code in dist/src/BLEService.mjs
(+3 more)
ADDITIONAL FINDINGS
- Reconstructed Obfuscated URL in dist/index.js: "https://www.google.com/maps?q=null,null"
- Suspicious URL Pattern in Template Literal in dist/index.js: "https://api.telegram.org/bot${...}/sendMessage"
PAYLOAD FILES
dist/index.mjs (+ dist/src/update.mjs)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | blekit | all (affected) | — |
Aliases
Browse GCVE Records
3,164 records in the GCVE database · Updated October 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.