VDB
GCVE-110-OSM-2026-13369
GCVE-110-OSM-2026-13369
Advisory PublishedCVSS 9.6/10
Contagious Interview Campaign
Trojanized Node.js/React application distributed as a fake-interview "coding challenge" lure, part of the DPRK-aligned Contagious Interview / DeceptiveDevelopment campaign (aka Famous Chollima). This repository 'Nexora' decoy (duplicate org of Holitix-tech). It hides an obfuscated JavaScript C2 stager that exfiltrates the host environment and provides eval-based remote code execution. Running the project, or merely npm install, executes the stager.
IOCs:
Repository: https://github.com/Holitix-studio/Nexora-mvp
GitHub org/account: Holitix-studio
Malicious file: routes/api/auth.js (main branch)
Install trigger: package.json "prepare" script: start /b node server || nohup node server &
C2 URL: http://51.77.188.54:1224/api/checkStatus
C2 IP: 51.77.188.54
C2 port: 1224/tcp
Beacon tag (tid param): bm93IGl0IHRpbWUgdG8gZ2V0IGV2ZXJ5dGhpbmc= (base64 of "now it time to get everything")
Attribution: DPRK Contagious Interview / DeceptiveDevelopment / Famous Chollima
A JavaScript stager is appended to routes/api/auth.js, placed on the same physical line as the legitimate module.exports = router; and pushed off-screen behind roughly 783 characters of whitespace padding (full line ~3,343 chars). It uses hex-named string-array obfuscation (_0x...) with a runtime-rotated array; the C2 URL and a beacon marker are stored base64-encoded and resolved at runtime.
Execution is automatic via two paths: (1) the file is require()'d at server boot through routes/index.js (app.use('/api/auth', require('./api/auth'))), and a bare top-level block runs on load; (2) package.json contains a prepare script (start /b node server || nohup node server &) that runs automatically on npm install, so installation alone detonates it. No HTTP request or manual run is required.
On execution it collects host info (hostname, OS platform/type/release, and the MAC of the first non-internal IPv4 interface) and exfiltrates the full process environment (JSON.stringify(process.env) i.e. any API keys, DB credentials and tokens) to the C2 as an HTTP GET query string. It beacons every 5 seconds (setInterval, 5000 ms). The C2 response is parsed as JSON {status, message, sysId}; when status === 'error', message is passed to eval(), giving arbitrary remote code execution. The eval channel is a second-stage loader consistent with BeaverTail / InvisibleFerret browser-credential and crypto-wallet stealers. Any ethers / wallet-connect code in the app is decoy functionality, not the theft mechanism.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Browse GCVE Records
3,130 records in the GCVE database · Updated October 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.