VDB

GCVE-110-OSM-2026-4073

GCVE-110-OSM-2026-4073
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published May 11, 2026
[osmalyze-auto] Malicious package detected. Behaviors: data exfiltration. [osmalyze-auto] Entrypoint: dist/esm/index.js (main: dist/esm/index.js) Exfil: https://your-gitlab.com/oauth/authorize (custom-c2, recovery: plaintext in dist/types/provider/gitlab.d.ts) Payload: dist/types/provider/slack.d.ts Secondary files: dist/types/provider/discord.d.ts, dist/types/provider/github.d.ts Key findings: - Environment Variable Exfiltration in dist/types/provider/discord.d.ts: "process.env.DISCORD_CLIENT_SECRET * } * ``` */ readonly clien..." - Environment Variable Exfiltration in dist/types/provider/facebook.d.ts: "process.env.FACEBOOK_APP_SECRET * } * ``` */ readonly clientS..." - Environment Variable Exfiltration in dist/types/provider/github.d.ts: "process.env.GITHUB_CLIENT_SECRET * } * ``` */ readonly client..." - Environment Variable Exfiltration in dist/types/provider/gitlab.d.ts: "process.env.GITLAB_CLIENT_SECRET * } * ``` */ readonly client..." - Environment Variable Exfiltration in dist/types/provider/google.d.ts: "process.env.GOOGLE_CLIENT_SECRET * } * ``` */ readonly client..." IOCs: - ipv4: 1.32.42.18, 181.54.78.241 - urls: https://accounts.spotify.com/authorize, https://accounts.spotify.com/api/token, https://id.twitch.tv/oauth2/authorize, https://id.twitch.tv/oauth2/token, https://your-gitlab.com/oauth/authorize (+11 more) - domains: login.microsoftonline.com, accounts.spotify.com, id.twitch.tv, www.terminal.shop, sst.dev (+14 more) - emails: user@contoso.com - payloadFileHash: 5982bb0f37f78442987d70a3d11f5c45c9fbb4c6433673d575c427a85f52d0fb

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@draftlab/auth0.24.0 (affected)

References

vendor

Browse GCVE Records

74,198 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›