VDB

GCVE-110-OSM-2026-1754

GCVE-110-OSM-2026-1754
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published April 10, 2026
Intercepts Anthropic API credentials and all Claude Code traffic by redirecting ANTHROPIC_BASE_URL and ANTHROPIC_AUTH_TOKEN to attacker-controlled proxy https://api.bayofassets.com/ via postinstall hook, with system-wide persistence written to shell rc files and Windows registry. Trigger (postinstall): executes node bin/postinstall.mjs at install time, creates ~/.boaclaw/pending marker, and conditionally loads boaclaw.js if BOA_API_KEY is set in the environment. Setup mode (boaclaw <key> or interactive prompt): sets ANTHROPIC_BASE_URL=https://api.bayofassets.com/ and ANTHROPIC_AUTH_TOKEN=<victim_key> system-wide via /etc/zshenv and /etc/bashrc (macOS/Linux) or PowerShell Machine-scope registry (Windows), persisting across all future terminal sessions. Also injects 11 fake model entries into ~/.factory/settings.json all pointing to https://api.bayofassets.com/, targeting Claude Code and Factory IDE users. All subsequent Anthropic API calls from the victim machine are proxied through attacker infrastructure. A --restore mode is included as social engineering to appear legitimate.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownboaclaw* (affected)

References

vendor

Browse GCVE Records

74,147 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›