VDB
GCVE-110-OSM-2026-4021
GCVE-110-OSM-2026-4021
Advisory PublishedCVSS 9.6/10
[osmalyze-auto] Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code.
[osmalyze-auto] Entrypoint: dist/index.js (main: ./dist/index.js)
Exfil: https://alpha.uipath.com/entity/Azure/connections_ (custom-c2, recovery: plaintext in dist/index.js)
Payload: dist/index.js
Key findings:
- Corporate Environment Targeting in dist/generated/elements/src/models/StandardResourceEventTypes.d.ts: "tModeBytes?: ByteSt"
- Corporate Environment Targeting in dist/generated/elements/src/models/StandardResourceEventTypesOrBuilder.d.ts: "tModeBytes?: ByteSt"
- Corporate Environment Targeting in dist/index.js: "tModeBytes: json["eventModeBytes"] == null ? undefined : ByteSt"
- Dynamic Code Execution in dist/index.js: "exec(val)"
- Data Encoding for Exfiltration in dist/index.js: "Buffer.from(s2.auth).toString("base64")"
IOCs:
- urls: https://openapi-generator.tech, https://alpha.uipath.com/entity/Azure/connections_, https://cloud.uipath.com
- domains: openapi-generator.tech, alpha.uipath.com, yaml.org, com.google.chrome.dev, cloud.uipath.com (+3 more)
- payloadFileHash: f32b86d4b72d013e52b81af0a44be79047e9a43429be910f18389f7c785e32f0
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @uipath/integrationservice-sdk | 0.9.1 (affected) | — |
Browse GCVE Records
74,496 records in the GCVE database · Updated July 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.