VDB
GCVE-110-OSM-2026-12839
GCVE-110-OSM-2026-12839
Advisory PublishedCVSS 8.8/10
@zaka13/thing@1.0.0 ships the same disguised in-browser proxy kit as webpackbootstrap5 and webpackbootstrapscripts by the same publisher (zaka13). Its YXBp.js loader matches those packages' index-z2b7r4.js (same sha256): it XOR-decodes endpoints with a fixed key, injects remote scripts from https://dyingefforlessefforlessours.com, and boots a Scramjet/wisp WebSocket proxy routing traffic through operator relays. The package presents itself as 'thingy' with an SVG main entry. Harm is browser-side when the asset is served; no install script runs.
ADDITIONAL FINDINGS
- Brand New Package
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @zaka13/thing | all (affected) | — |
Aliases
Browse GCVE Records
3,164 records in the GCVE database · Updated October 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.