VDB

GCVE-110-OSM-2026-3981

GCVE-110-OSM-2026-3981
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published May 11, 2026
[osmalyze-auto] Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code. [osmalyze-auto] Entrypoint: dist/cjs/index.cjs (main: dist/cjs/index.cjs) Exfil: https://npms.io/search?q=ponyfill. (custom-c2, recovery: plaintext in router_init.js) Payload: router_init.js Key findings: - Environment Variable Exfiltration in router_init.js: "process.env,_0x1dfe59=await _0x1ffb45[_0x25960e(0x1993)](fetch" - Data Encoding for Exfiltration in dist/cjs/path.cjs: "encodeURIComponent(char), char" - Data Encoding for Exfiltration in dist/cjs/ssr/serializer/RawStream.cjs: "btoa(" - Dynamic Base64 Decoding in dist/cjs/ssr/serializer/RawStream.cjs: "atob(base64)" - Dynamic Code Execution in dist/cjs/utils.cjs: "exec(path)" IOCs: - urls: https://tanstack.com/router, https://tanstack.com/router/latest/docs/framework/react/api/router/deferFunction, https://tanstack.com/router/latest/docs/framework/react/api/router/deferFunction\n, https://tanstack.com/router/latest/docs/framework/react/api/router/NavigateOptionsType, https://tanstack.com/router/latest/docs/router/framework/react/api/router/notFoundFunction (+28 more) - domains: static.scarf.sh, tanstack.com, developer.chrome.com, npms.io, vnd.dev (+2 more) - payloadFileHash: ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@tanstack/router-core1.169.8 (affected)

Browse GCVE Records

74,366 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›