VDB

GCVE-110-OSM-2026-13093

GCVE-110-OSM-2026-13093
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published October 3, 2026
lib/config.js:1 is obfuscator.io-obfuscated code containing fs requires, {execSync, spawn} from child_process, two obfuscated execSync() shell executions, and a silent detached spawn with windowsHide/stdio-ignore — covert shell execution and process launching that no legitimate logger/config module performs. The clean-looking index.js wrapper exists only to load this payload. ## Static analysis (vigil) Verdict `BLOCK`, score 55/100. Critical/high findings: - [critical] SC-015 Shell command execution — `package/lib/config.js:1` - [critical] SC-015 Shell command execution — `package/lib/config.js:1` - [high] OBF-028 Obfuscator.io string-array rotation — `package/lib/config.js:1` ## Package metadata - Publisher: unknown - Published: 2026-10-03T01:59:53.619Z - Install hooks: none found - SHA-256 (tarball): `d702fb3adb8f86db3cfd1a6f6b8f13ce35f288fbbd031cb5eaa21e27722b34d3` ## IOCs (defanged) - hk[.]me - hm[.]me - obfuscator[.]io - py[.]io - zg[.]me

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownhardhat-jsx2.0.1 (affected)—

References

vendor

Browse GCVE Records

3,164 records in the GCVE database · Updated October 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›