VDB

GCVE-110-OSM-2026-4333

GCVE-110-OSM-2026-4333
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published May 19, 2026
TeamPCP has compromised the NPM user atool who maintains over 500+ NPM packages. [osmalyze-auto] Entrypoint: lib/index.js (main: lib/index.js) Payload: index.js Key findings: - Environment Variable Exfiltration in index.js: "process.env,_0x40cf8c=await fetch" - Data Encoding for Exfiltration in index.js: "encodeURIComponent(_0x46231f),_0x502c3c=await fetch(_0x38f633(_0x5c64d5._0x25361..." - Obfuscation: augmented proxied array function replacements in index.js - Obfuscation Pattern: hexVariables in index.js: "_0x192368" IOCs: - domains: awesome.re, facebook.github.io - emails: i@hust.cc - payloadFileHash: e37e3ddeeaaa9e0c4fdbcb829b4895a6521031c80053fc436625b61e6ee5b1a6

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownjest-canvas-mock

References

vendor

Browse GCVE Records

74,608 records in the GCVE database · Updated July 24, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›