VDB

GCVE-110-OSM-2026-12847

GCVE-110-OSM-2026-12847
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published September 30, 2026
The package is a Facebook/Messenger client, but its default login recovery sends Facebook credentials and optional 2FA secrets to a third-party endpoint controlled by the attacker. It sends email, password, and optionally the Base32 2FA secret, then accepts returned Facebook cookies/access tokens. PERSISTENCE - Startup Persistence in src/api/action/changeAvatar.js: ".profile" - Startup Persistence in src/api/users/getUserInfo.js: ".profile" - Startup Persistence in src/api/users/getUserInfoV2.js: ".profile" - Startup Persistence in src/app/threadInfoRealtimeSync.js: ".profile" - Startup Persistence in src/utils/nexca-utils.js: ".profile" - Startup Persistence in src/vendor/fca-unofficial/src/getUserInfo.js: ".profile" - Startup Persistence in src/vendor/fca-unofficial/src/portedProfileAndSearch.js: ".profile" - Startup Persistence in src/vendor/fca-unofficial/src/portedSocial.js: ".profile" DESTINATION - 17 exfil (custom-c2, reconstructed) - 1 c2 (domains) - 1 fetched-payload (deobfuscated) (values recorded in verified_iocs) EXFIL - Environment Variable Exfiltration in src/api/socket/e2ee/e2ee/vendor/fb-e2ee.cjs: "process.env.FB_E2EE_MEDIA_UPLOAD_AUTH ? { host: process.env.FB_E2EE_MEDIA_UPLOAD..." - Environment Variable Exfiltration in src/api/socket/e2ee/vendor/fb-e2ee.cjs: "process.env.FB_E2EE_MEDIA_UPLOAD_AUTH ? { host: process.env.FB_E2EE_MEDIA_UPLOAD..." - Data Encoding for Exfiltration in src/api/action/setPostReaction.js: "Buffer.from("feedback:" + postID).toString("base64")" - Data Encoding for Exfiltration in src/api/messaging/uploadAttachment.js: "encodeURIComponent(userId" - Data Encoding for Exfiltration in src/api/socket/e2ee/e2ee/native/lib/index.mjs: "Buffer.from(bytes).toString("base64")" - HTTP Data Exfiltration in src/api/socket/e2ee/e2ee/nativeBridge.js: "fetchable attachment.url ───────────────────────────────────────── const MEDIA_C..." - Data Encoding for Exfiltration in src/api/socket/e2ee/e2ee/vendor/fb-e2ee.cjs: "Buffer.from([5]).toString("base64")" - Data Encoding for Exfiltration in src/api/socket/e2ee/native/lib/index.mjs: "Buffer.from(bytes).toString("base64")" (+13 more) OBFUSCATION - IOCs Found in Deobfuscated Code in src/api/socket/e2ee/e2ee/native/lib/index.mjs - IOCs Found in Deobfuscated Code in src/api/socket/e2ee/e2ee/ratchet.js - IOCs Found in Deobfuscated Code in src/api/socket/e2ee/native/lib/index.mjs - IOCs Found in Deobfuscated Code in src/api/socket/e2ee/ratchet.js - Dynamic Base64 Decoding in src/api/socket/e2ee/e2ee/native/lib/index.mjs: "Buffer.from(trimmed, "base64")" - Dynamic Base64 Decoding in src/api/socket/e2ee/e2ee/ratchet.js: "Buffer.from(v, "base64")" - Dynamic Base64 Decoding in src/api/socket/e2ee/e2ee/store.js: "Buffer.from(data, "base64")" - Dynamic Base64 Decoding in src/api/socket/e2ee/e2ee/vendor/fb-e2ee.cjs: "Buffer.from(id, "base64")" (+11 more) ADDITIONAL FINDINGS - Platform Detection with Data Collection in src/api/messaging/createThemeAI.js: "JSON.stringify({ input: { client_mutation_id: Math.round(Math.random() * 19).toS" - Dynamic Code Execution in src/api/messaging/uploadAttachment.js: "exec(s)" - Suspicious URL Pattern in Template Literal in src/api/messaging/uploadAttachment.js: "https://www.facebook.com/ajax/mercury/upload.php?${...}" - Brand New Package - Very New NPM Publisher Account - Rapid Version Publishing PAYLOAD FILES src/api/messaging/uploadAttachment.js (+ src/api/socket/e2ee/e2ee/vendor/fb-e2ee.cjs, src/api/socket/e2ee/vendor/fb-e2ee.cjs)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownfca-raihanall (affected)—

References

advisory
vendor

Browse GCVE Records

3,105 records in the GCVE database · Updated October 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›