VDB
GCVE-110-OSM-2026-3981
GCVE-110-OSM-2026-3981
Advisory PublishedCVSS 9.6/10
[osmalyze-auto] Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code.
[osmalyze-auto] Entrypoint: dist/cjs/index.cjs (main: dist/cjs/index.cjs)
Exfil: https://npms.io/search?q=ponyfill. (custom-c2, recovery: plaintext in router_init.js)
Payload: router_init.js
Key findings:
- Environment Variable Exfiltration in router_init.js: "process.env,_0x1dfe59=await _0x1ffb45[_0x25960e(0x1993)](fetch"
- Data Encoding for Exfiltration in dist/cjs/path.cjs: "encodeURIComponent(char), char"
- Data Encoding for Exfiltration in dist/cjs/ssr/serializer/RawStream.cjs: "btoa("
- Dynamic Base64 Decoding in dist/cjs/ssr/serializer/RawStream.cjs: "atob(base64)"
- Dynamic Code Execution in dist/cjs/utils.cjs: "exec(path)"
IOCs:
- urls: https://tanstack.com/router, https://tanstack.com/router/latest/docs/framework/react/api/router/deferFunction, https://tanstack.com/router/latest/docs/framework/react/api/router/deferFunction\n, https://tanstack.com/router/latest/docs/framework/react/api/router/NavigateOptionsType, https://tanstack.com/router/latest/docs/router/framework/react/api/router/notFoundFunction (+28 more)
- domains: static.scarf.sh, tanstack.com, developer.chrome.com, npms.io, vnd.dev (+2 more)
- payloadFileHash: ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @tanstack/router-core | 1.169.8 (affected) | — |
Browse GCVE Records
74,366 records in the GCVE database · Updated July 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.