VDB

GCVE-110-OSM-2026-4062

GCVE-110-OSM-2026-4062
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published May 11, 2026
[osmalyze-auto] Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code, install-time execution. [osmalyze-auto] Entrypoint: setup.mjs (install-hook: node setup.mjs) Exfil: https://fulcio.sigstore.dev (custom-c2, recovery: plaintext in router_init.js) Payload: router_init.js Key findings: - Environment Variable Exfiltration in router_init.js: "process.env,_0x29abe1=await _0x1186c8[_0x14fc47(0x2a2e)](fetch" - Download Execute Delete Pattern in setup.mjs: "writeFileSync(dt, fd); } function xb(zp, en, od) { if (hc("unzip", ["-v"])) {..." - Install Hook Executes Local JS File in package.json: ""preinstall": "node setup.mjs"" - Indirect Function Constructor Access in router_init.js: "['constructor']" - Data Encoding for Exfiltration in router_init.js: "encodeURIComponent(_0xfabeab)+_0x20353a(0xa94);try{let _0x2e3c0c=await _0x4f3baf..." IOCs: - urls: https://id.winks.io/ids, https://id.winks.io/ids/connect/authorize, https://id.winks.io/ids/connect/token, https://id.winks.io/ids/connect/userinfo, https://beproduct.com/docs (+1 more) - domains: id.winks.io, beproduct.com, seed1.getsession.org, seed3.getsession.org, fulcio.sigstore.dev (+1 more) - sha256Hashes: c430d44666289dae81f30fa7b2edebf186ecc91a2d4c71266ea6ae76388792e1, 45b7ab580deca34ae9729e97c13cfd999df04416a79116c3bfb483804f85ded4, 3facaf05f0c5fc569c5649dd359892c98a85557e3e0c847964caeb67076f4d75, e44bb8bbac7f10ecc786703fe0a6a4b952189f908707980ba8f3c8975a760962, 5e1c4c362065a6b95ff952c0eab010f04dcd2c3494e813b493ecfd4fcb9fc0d8 (+45 more) - payloadFileHash: 29c729852fce5a53e30a1541d9fec79c915b2e13f1eda94a5978cf0aae0d88d9

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@beproduct/nestjs-auth0.1.17 (affected)

Browse GCVE Records

73,873 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›