VDB

GCVE-110-OSM-2026-13369

GCVE-110-OSM-2026-13369
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published October 6, 2026
Contagious Interview Campaign Trojanized Node.js/React application distributed as a fake-interview "coding challenge" lure, part of the DPRK-aligned Contagious Interview / DeceptiveDevelopment campaign (aka Famous Chollima). This repository 'Nexora' decoy (duplicate org of Holitix-tech). It hides an obfuscated JavaScript C2 stager that exfiltrates the host environment and provides eval-based remote code execution. Running the project, or merely npm install, executes the stager. IOCs: Repository: https://github.com/Holitix-studio/Nexora-mvp GitHub org/account: Holitix-studio Malicious file: routes/api/auth.js (main branch) Install trigger: package.json "prepare" script: start /b node server || nohup node server & C2 URL: http://51.77.188.54:1224/api/checkStatus C2 IP: 51.77.188.54 C2 port: 1224/tcp Beacon tag (tid param): bm93IGl0IHRpbWUgdG8gZ2V0IGV2ZXJ5dGhpbmc= (base64 of "now it time to get everything") Attribution: DPRK Contagious Interview / DeceptiveDevelopment / Famous Chollima A JavaScript stager is appended to routes/api/auth.js, placed on the same physical line as the legitimate module.exports = router; and pushed off-screen behind roughly 783 characters of whitespace padding (full line ~3,343 chars). It uses hex-named string-array obfuscation (_0x...) with a runtime-rotated array; the C2 URL and a beacon marker are stored base64-encoded and resolved at runtime. Execution is automatic via two paths: (1) the file is require()'d at server boot through routes/index.js (app.use('/api/auth', require('./api/auth'))), and a bare top-level block runs on load; (2) package.json contains a prepare script (start /b node server || nohup node server &) that runs automatically on npm install, so installation alone detonates it. No HTTP request or manual run is required. On execution it collects host info (hostname, OS platform/type/release, and the MAC of the first non-internal IPv4 interface) and exfiltrates the full process environment (JSON.stringify(process.env) i.e. any API keys, DB credentials and tokens) to the C2 as an HTTP GET query string. It beacons every 5 seconds (setInterval, 5000 ms). The C2 response is parsed as JSON {status, message, sysId}; when status === 'error', message is passed to eval(), giving arbitrary remote code execution. The eval channel is a second-stage loader consistent with BeaverTail / InvisibleFerret browser-credential and crypto-wallet stealers. Any ethers / wallet-connect code in the app is decoy functionality, not the theft mechanism.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)—

Browse GCVE Records

3,130 records in the GCVE database · Updated October 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›