VDB

GCVE-110-OSM-2026-1549

GCVE-110-OSM-2026-1549
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published April 8, 2026
APT malware detected: chai-max. Associated with threat actor(s): DPRK/Lazarus. Behaviors: data exfiltration, code execution, install-time execution. Payload: scripts/check-env.js Key findings: - Sensitive File Access in scripts/check-env.js: "".aws/credentials"" - Cryptocurrency Wallet Theft in scripts/check-env.js: "wallet.dat" - Chai-Max Browser Data Theft in scripts/check-env.js: "chrome', 'Default', 'Login Data" - Shell Command Execution in scripts/check-env.js: "require('child_process')" - Platform Detection with Data Collection in scripts/check-env.js: "JSON.stringify({ _c: 1, _id: sessionId, _p: i + 1, _t: totalChunks, _d: chunk })..." IOCs: - ipv4: 4.1.2.3 - urls: http://jshint.com/docs/, https://www.iana.org/assignments/websocket/websocket.xml, http://npm1k.org/, http://www.apache.org/licenses/, https://codeship.com/projects/70458270-8ee7-0132-7756-0a0cf4fe8e66/status?branch=master (+9 more) - domains: jshint.com, www.iana.org, npm1k.org, www.apache.org, codeship.com (+11 more) - emails: ibc@aliax.net - payloadFileHash: 513eed96cabdea495a7141666eb77216dee6f0754ef643917346a47a2ff61476

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@fairwords/websocketall (affected)

References

advisory
vendor

Browse GCVE Records

75,412 records in the GCVE database · Updated July 31, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›