VDB

GCVE-110-OSM-2026-13394

GCVE-110-OSM-2026-13394
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published October 8, 2026
This package masquerades as a corporate SSO wrapper for Claude Code but the main binary `dist/bin/bf.js` contains a download-execute-delete dropper pattern (`spawnSync`/`spawn`/`unlink` triad), dynamic code execution via `exec(x)`, and hardcoded endpoints classified as custom-C2 — including the externally-routable domains `b.rgb.xyz` and `b.xyz`, which no legitimate corporate SSO product would use as authentication infrastructure. The attacker model is a credential harvester: the CLI collects username/password pairs via the fake `auth/login` and `auth/refresh` flows (`JSON.stringify({username:e,password:t})`, `JSON.stringify({refresh_token:e})`), then exfils them to attacker-controlled external domains under the guise of 'office-network-only' operation. The private IPs (10.202.171.20:8001, 10.190.7.99:8008) are consistent with targeting a specific corporate environment. The postinstall hook additionally installs Claude Code plugins from third-party GitHub repos under attacker control (`FarhanRiuzaki/Mega-SDD.git`), providing persistent code execution surface. Brand-new publisher with only two related packages and no source repository reinforces the adversarial profile. ENTRY scripts/postinstall.mjs (install-hook: node scripts/postinstall.mjs) - Install Hook Executes Local JS File in package.json DESTINATION - 4 exfil (custom-c2) (values recorded in verified_iocs) EXFIL - Data Encoding for Exfiltration in dist/bin/bf.js: "encodeURIComponent(n)}:${encodeURIComponent(i)}@${a.proxy}`:void 0,x=null;if(pro..." - System Information Collection in dist/bin/bf.js: "process.platform" - System Information Collection in scripts/postinstall.mjs: "process.platform" OBFUSCATION - Hex Encoded Strings in dist/bin/bf.js: ""\x80\x81\x82\x83\x84\x85\x86\x87\x88\x89\x8A\x8B\x8C\x8D\x8E\x8F\x90\x91\x92\x9..." - Unicode Escape Obfuscation in dist/bin/bf.js: "\uD83C\uDFF4\uDB40\uDC67\uDB40\uDC62" - Obfuscation patterns: unicodeHeavy, hexHeavy in dist/bin/bf.js ADDITIONAL FINDINGS - Download Execute Delete Pattern in dist/bin/bf.js: "spawn as hx,spawnSync as px}from"child_process";import{readFileSync as Dx,unlink" - Dynamic Code Execution in dist/bin/bf.js: "exec(x)" - Shell Command Variable Setup in dist/bin/bf.js: "win32",a=s?process.env.ComSpec||"cmd.exe":r,o=s?["/c",r,...e]:e;au(a,o,{env:t,ti..." - Platform Detection with Data Collection in dist/bin/bf.js: "JSON.stringify({username:e,password:t})})}async function Ks(r,e){return yn(`${r}..." - Shell Command Execution in scripts/postinstall.mjs: "spawnSync(" - Brand New Package (+1 more) PAYLOAD FILES dist/bin/bf.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownmega-code-devall (affected)—

References

vendor

Browse GCVE Records

3,328 records in the GCVE database · Updated October 10, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›