VDB
GCVE-110-OSM-2026-4073
GCVE-110-OSM-2026-4073
Advisory PublishedCVSS 9.6/10
[osmalyze-auto] Malicious package detected. Behaviors: data exfiltration.
[osmalyze-auto] Entrypoint: dist/esm/index.js (main: dist/esm/index.js)
Exfil: https://your-gitlab.com/oauth/authorize (custom-c2, recovery: plaintext in dist/types/provider/gitlab.d.ts)
Payload: dist/types/provider/slack.d.ts
Secondary files: dist/types/provider/discord.d.ts, dist/types/provider/github.d.ts
Key findings:
- Environment Variable Exfiltration in dist/types/provider/discord.d.ts: "process.env.DISCORD_CLIENT_SECRET
* }
* ```
*/
readonly clien..."
- Environment Variable Exfiltration in dist/types/provider/facebook.d.ts: "process.env.FACEBOOK_APP_SECRET
* }
* ```
*/
readonly clientS..."
- Environment Variable Exfiltration in dist/types/provider/github.d.ts: "process.env.GITHUB_CLIENT_SECRET
* }
* ```
*/
readonly client..."
- Environment Variable Exfiltration in dist/types/provider/gitlab.d.ts: "process.env.GITLAB_CLIENT_SECRET
* }
* ```
*/
readonly client..."
- Environment Variable Exfiltration in dist/types/provider/google.d.ts: "process.env.GOOGLE_CLIENT_SECRET
* }
* ```
*/
readonly client..."
IOCs:
- ipv4: 1.32.42.18, 181.54.78.241
- urls: https://accounts.spotify.com/authorize, https://accounts.spotify.com/api/token, https://id.twitch.tv/oauth2/authorize, https://id.twitch.tv/oauth2/token, https://your-gitlab.com/oauth/authorize (+11 more)
- domains: login.microsoftonline.com, accounts.spotify.com, id.twitch.tv, www.terminal.shop, sst.dev (+14 more)
- emails: user@contoso.com
- payloadFileHash: 5982bb0f37f78442987d70a3d11f5c45c9fbb4c6433673d575c427a85f52d0fb
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @draftlab/auth | 0.24.0 (affected) | — |
Browse GCVE Records
74,198 records in the GCVE database · Updated July 21, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.