VDB

GCVE-110-OSM-2026-2661

GCVE-110-OSM-2026-2661
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published April 17, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, network activity, obfuscated code. Payload: dist/internal/runner/executor.js Secondary files: dist/internal/config/constants.d.ts, dist/internal/config/constants.js Key findings: - Fetch and Eval/Exec in dist/internal/runner/executor.js: "await axios.get(src, { headers: { [k]: v } }); ..." - Decoded Base64 Content in dist/internal/config/constants.d.ts - Decoded Base64 Content in dist/internal/config/constants.js - Dynamic Code Execution in dist/internal/runner/executor.js: "new Function("require", dynamicCode)" - Payload Download from Paste Service in dist/internal/runner/executor.js: "jsonkeeper.com" IOCs: - urls: https://jsonkeeper.com/b/ADPEC - domains: jsonkeeper.com - payloadFileHash: 40877090fb549534037b75a7370cbdcca07f528ee9e56bd257800661b556e094 Decoded/deobfuscated IOCs: - urls: https://jsonkeeper.com/b/ADPEC - domains: jsonkeeper.com

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownvite-enhancer-config1.2.6 (affected)

Browse GCVE Records

74,267 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›