VDB

GCVE-110-OSM-2026-12760

GCVE-110-OSM-2026-12760
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published September 22, 2026
package.json declares the runtime dependency `libsignal` as `github:tenka-san/libsignal-node` rather than a registry version range or pinned commit SHA. On `npm install`, npm fetches the current HEAD of that fork's default branch and executes any lifecycle scripts it defines. The fork is under a third-party GitHub account (not the upstream WhiskeySockets libsignal-node maintainer), has no commit pin, and no integrity check, so whoever controls that account controls code that runs on the installer's machine at install time. The package presents as a Baileys/WhatsApp library fork; the static match on lib/Utils/generics.js line 403 (ping/GET tokens) is consistent with normal Baileys network code and is not independently indicative of exfiltration. ENTRY engine-requirements.js (install-hook: node ./engine-requirements.js) - Install Hook Executes Local JS File in package.json PERSISTENCE - Startup Persistence in lib/Socket/chats.js: ".profile" - Startup Persistence in lib/Socket/messages-send.js: ".profile" DESTINATION - 5 exfil (custom-c2) (values recorded in verified_iocs) EXFIL - Data Encoding for Exfiltration in lib/Socket/ban-checker.js: "encodeURIComponent(num)}&type=phone_number&app_absent=0" - Data Encoding for Exfiltration in lib/Socket/socket.js: "Buffer.from(creds.noiseKey.public).toString('base64')" - Data Encoding for Exfiltration in lib/Utils/chat-utils.js: "Buffer.from(indexMac).toString('base64')" - Data Encoding for Exfiltration in lib/Utils/generics.js: "Buffer.from(value?.data || value).toString('base64')" - Data Encoding for Exfiltration in lib/Utils/messages-media.js: "Buffer.from(media.fileSha256).toString('base64')" - Data Encoding for Exfiltration in lib/Utils/process-message.js: "Buffer.from(keyId.keyId).toString('base64')" - Network Request in lib/Utils/generics.js: "fetch('https:" - Network Request in lib/Utils/messages-media.js: "request({ hostname: parsedUrl.hostname, port: parsedUrl.port || (parsedUrl.proto..." OBFUSCATION - Dynamic Base64 Decoding in lib/Utils/chat-utils.js: "Buffer.from(keyId, 'base64')" - Dynamic Base64 Decoding in lib/Utils/decode-wa-message.js: "Buffer.from(secret, 'base64')" - Dynamic Base64 Decoding in lib/Utils/validate-connection.js: "Buffer.from(advSecretKey, 'base64')" - String Array Obfuscation in lib/Utils/message-composer.js: "[ 'import', 'export', 'from', 'default', 'as', 'const', 'let', 'var', 'function'..." - String Array Obfuscation in lib/Utils/messages.js: "[ 'break', 'case', 'catch', 'continue', 'debugger', 'default', 'delete', 'do', '..." - String Array Obfuscation in lib/WABinary/constants.js: "[ '1724', 'profile_picture', '1071', '1314', '1605', '407', '990', '1710', '746'..." - Decoded Base64 Content in lib/Socket/newsletter.js - Strings Extracted from Deobfuscated Code in lib/Utils/chat-utils.js (+2 more) ADDITIONAL FINDINGS - Dynamic Code Execution in lib/Utils/message-composer.js: "exec(line)" - Publisher Shows Burner-Account Pattern PAYLOAD FILES lib/Utils/generics.js (+ lib/Utils/messages-media.js, lib/Utils/chat-utils.js) ## Additional context: PhantomSub campaign - Channel IDs are embedded in the package source (variant not stated in source for this package).

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownnoverojavaall (affected)—

References

advisory
vendor

Browse GCVE Records

3,112 records in the GCVE database · Updated October 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›