VDB
GCVE-110-OSM-2026-12847
GCVE-110-OSM-2026-12847
Advisory PublishedCVSS 8.8/10
The package is a Facebook/Messenger client, but its default login recovery sends Facebook credentials and optional 2FA secrets to a third-party endpoint controlled by the attacker. It sends email, password, and optionally the Base32 2FA secret, then accepts returned Facebook cookies/access tokens.
PERSISTENCE
- Startup Persistence in src/api/action/changeAvatar.js: ".profile"
- Startup Persistence in src/api/users/getUserInfo.js: ".profile"
- Startup Persistence in src/api/users/getUserInfoV2.js: ".profile"
- Startup Persistence in src/app/threadInfoRealtimeSync.js: ".profile"
- Startup Persistence in src/utils/nexca-utils.js: ".profile"
- Startup Persistence in src/vendor/fca-unofficial/src/getUserInfo.js: ".profile"
- Startup Persistence in src/vendor/fca-unofficial/src/portedProfileAndSearch.js: ".profile"
- Startup Persistence in src/vendor/fca-unofficial/src/portedSocial.js: ".profile"
DESTINATION
- 17 exfil (custom-c2, reconstructed)
- 1 c2 (domains)
- 1 fetched-payload (deobfuscated)
(values recorded in verified_iocs)
EXFIL
- Environment Variable Exfiltration in src/api/socket/e2ee/e2ee/vendor/fb-e2ee.cjs: "process.env.FB_E2EE_MEDIA_UPLOAD_AUTH ? { host: process.env.FB_E2EE_MEDIA_UPLOAD..."
- Environment Variable Exfiltration in src/api/socket/e2ee/vendor/fb-e2ee.cjs: "process.env.FB_E2EE_MEDIA_UPLOAD_AUTH ? { host: process.env.FB_E2EE_MEDIA_UPLOAD..."
- Data Encoding for Exfiltration in src/api/action/setPostReaction.js: "Buffer.from("feedback:" + postID).toString("base64")"
- Data Encoding for Exfiltration in src/api/messaging/uploadAttachment.js: "encodeURIComponent(userId"
- Data Encoding for Exfiltration in src/api/socket/e2ee/e2ee/native/lib/index.mjs: "Buffer.from(bytes).toString("base64")"
- HTTP Data Exfiltration in src/api/socket/e2ee/e2ee/nativeBridge.js: "fetchable attachment.url ───────────────────────────────────────── const MEDIA_C..."
- Data Encoding for Exfiltration in src/api/socket/e2ee/e2ee/vendor/fb-e2ee.cjs: "Buffer.from([5]).toString("base64")"
- Data Encoding for Exfiltration in src/api/socket/e2ee/native/lib/index.mjs: "Buffer.from(bytes).toString("base64")"
(+13 more)
OBFUSCATION
- IOCs Found in Deobfuscated Code in src/api/socket/e2ee/e2ee/native/lib/index.mjs
- IOCs Found in Deobfuscated Code in src/api/socket/e2ee/e2ee/ratchet.js
- IOCs Found in Deobfuscated Code in src/api/socket/e2ee/native/lib/index.mjs
- IOCs Found in Deobfuscated Code in src/api/socket/e2ee/ratchet.js
- Dynamic Base64 Decoding in src/api/socket/e2ee/e2ee/native/lib/index.mjs: "Buffer.from(trimmed, "base64")"
- Dynamic Base64 Decoding in src/api/socket/e2ee/e2ee/ratchet.js: "Buffer.from(v, "base64")"
- Dynamic Base64 Decoding in src/api/socket/e2ee/e2ee/store.js: "Buffer.from(data, "base64")"
- Dynamic Base64 Decoding in src/api/socket/e2ee/e2ee/vendor/fb-e2ee.cjs: "Buffer.from(id, "base64")"
(+11 more)
ADDITIONAL FINDINGS
- Platform Detection with Data Collection in src/api/messaging/createThemeAI.js: "JSON.stringify({ input: { client_mutation_id: Math.round(Math.random() * 19).toS"
- Dynamic Code Execution in src/api/messaging/uploadAttachment.js: "exec(s)"
- Suspicious URL Pattern in Template Literal in src/api/messaging/uploadAttachment.js: "https://www.facebook.com/ajax/mercury/upload.php?${...}"
- Brand New Package
- Very New NPM Publisher Account
- Rapid Version Publishing
PAYLOAD FILES
src/api/messaging/uploadAttachment.js (+ src/api/socket/e2ee/e2ee/vendor/fb-e2ee.cjs, src/api/socket/e2ee/vendor/fb-e2ee.cjs)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | fca-raihan | all (affected) | — |
Aliases
Browse GCVE Records
3,105 records in the GCVE database · Updated October 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.