VDB
GCVE-110-OSM-2026-13394
GCVE-110-OSM-2026-13394
Advisory PublishedCVSS 9.6/10
This package masquerades as a corporate SSO wrapper for Claude Code but the main binary `dist/bin/bf.js` contains a download-execute-delete dropper pattern (`spawnSync`/`spawn`/`unlink` triad), dynamic code execution via `exec(x)`, and hardcoded endpoints classified as custom-C2 — including the externally-routable domains `b.rgb.xyz` and `b.xyz`, which no legitimate corporate SSO product would use as authentication infrastructure. The attacker model is a credential harvester: the CLI collects username/password pairs via the fake `auth/login` and `auth/refresh` flows (`JSON.stringify({username:e,password:t})`, `JSON.stringify({refresh_token:e})`), then exfils them to attacker-controlled external domains under the guise of 'office-network-only' operation. The private IPs (10.202.171.20:8001, 10.190.7.99:8008) are consistent with targeting a specific corporate environment. The postinstall hook additionally installs Claude Code plugins from third-party GitHub repos under attacker control (`FarhanRiuzaki/Mega-SDD.git`), providing persistent code execution surface. Brand-new publisher with only two related packages and no source repository reinforces the adversarial profile.
ENTRY
scripts/postinstall.mjs (install-hook: node scripts/postinstall.mjs)
- Install Hook Executes Local JS File in package.json
DESTINATION
- 4 exfil (custom-c2)
(values recorded in verified_iocs)
EXFIL
- Data Encoding for Exfiltration in dist/bin/bf.js: "encodeURIComponent(n)}:${encodeURIComponent(i)}@${a.proxy}`:void 0,x=null;if(pro..."
- System Information Collection in dist/bin/bf.js: "process.platform"
- System Information Collection in scripts/postinstall.mjs: "process.platform"
OBFUSCATION
- Hex Encoded Strings in dist/bin/bf.js: ""\x80\x81\x82\x83\x84\x85\x86\x87\x88\x89\x8A\x8B\x8C\x8D\x8E\x8F\x90\x91\x92\x9..."
- Unicode Escape Obfuscation in dist/bin/bf.js: "\uD83C\uDFF4\uDB40\uDC67\uDB40\uDC62"
- Obfuscation patterns: unicodeHeavy, hexHeavy in dist/bin/bf.js
ADDITIONAL FINDINGS
- Download Execute Delete Pattern in dist/bin/bf.js: "spawn as hx,spawnSync as px}from"child_process";import{readFileSync as Dx,unlink"
- Dynamic Code Execution in dist/bin/bf.js: "exec(x)"
- Shell Command Variable Setup in dist/bin/bf.js: "win32",a=s?process.env.ComSpec||"cmd.exe":r,o=s?["/c",r,...e]:e;au(a,o,{env:t,ti..."
- Platform Detection with Data Collection in dist/bin/bf.js: "JSON.stringify({username:e,password:t})})}async function Ks(r,e){return yn(`${r}..."
- Shell Command Execution in scripts/postinstall.mjs: "spawnSync("
- Brand New Package
(+1 more)
PAYLOAD FILES
dist/bin/bf.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | mega-code-dev | all (affected) | — |
Browse GCVE Records
3,328 records in the GCVE database · Updated October 10, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.