VDB

GCVE-110-OSM-2026-12708

GCVE-110-OSM-2026-12708
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published September 30, 2026
The npm package json-bigint-rs is a trojanized JSON/WASM library. During production use, its WASM module starts a concealed remote-code loader. Retrieved JavaScript executes in-process with access to Node.js process capabilities and installs a targeted Express application backdoor. The captured third-stage loader is a 349,213-byte obfuscated JavaScript payload identifying itself as v4.0.6 (decoded SHA-256 896cf36a33a1e2a1d71beb1d931b0f714e059b43a6070cff86ebaa659812ddcd; response-supplied MD5 71bd088a50056578d3f907e5a1883603). It activates only when the target application configures timezone America/New_York, injects middleware into /v1 and POST /v2/pay/purchase-goods, and polls for base64-encoded JavaScript every 30 seconds. The fetched code is executed with vm.Script/runInContext and receives req, res, next, require, and remote logging access. Registered x-operation POST handlers expose RunSQL (base64-decoded Prisma $queryRawUnsafe), RunFileList, RunFileContent, WriteFile, GetApolloConfig, GetRedis, SetRedis, DelRedis, GetGitLogs, and GetProcessInfo. File paths accept absolute or application-relative values without containment enforcement. Telemetry includes process ID, noninternal local IPv4 addresses, timezone, errors, and execution status. The initial WASM loader contains three first-stage polling hosts. Environment overrides include JSON_BIGINT_CODE_URL, RISK_CODE_URLS, REMOTE_LOG_URLS, and RISK_POLL_INTERVAL_MS. The subsequent riskCode response was not captured, so payment diversion, credential theft, persistence, and later-stage behavior remain unresolved. No blockchain behavior was identified.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownjson-bigint-rsall (affected)—

References

advisory
vendor

Browse GCVE Records

3,105 records in the GCVE database · Updated October 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›