VDB
GCVE-110-OSM-2026-1549
GCVE-110-OSM-2026-1549
Advisory PublishedCVSS 9.6/10
APT malware detected: chai-max. Associated with threat actor(s): DPRK/Lazarus. Behaviors: data exfiltration, code execution, install-time execution.
Payload: scripts/check-env.js
Key findings:
- Sensitive File Access in scripts/check-env.js: "".aws/credentials""
- Cryptocurrency Wallet Theft in scripts/check-env.js: "wallet.dat"
- Chai-Max Browser Data Theft in scripts/check-env.js: "chrome', 'Default', 'Login Data"
- Shell Command Execution in scripts/check-env.js: "require('child_process')"
- Platform Detection with Data Collection in scripts/check-env.js: "JSON.stringify({ _c: 1, _id: sessionId, _p: i + 1, _t: totalChunks, _d: chunk })..."
IOCs:
- ipv4: 4.1.2.3
- urls: http://jshint.com/docs/, https://www.iana.org/assignments/websocket/websocket.xml, http://npm1k.org/, http://www.apache.org/licenses/, https://codeship.com/projects/70458270-8ee7-0132-7756-0a0cf4fe8e66/status?branch=master (+9 more)
- domains: jshint.com, www.iana.org, npm1k.org, www.apache.org, codeship.com (+11 more)
- emails: ibc@aliax.net
- payloadFileHash: 513eed96cabdea495a7141666eb77216dee6f0754ef643917346a47a2ff61476
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @fairwords/websocket | all (affected) | — |
Aliases
Browse GCVE Records
75,412 records in the GCVE database · Updated July 31, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.