VDB

GCVE-110-OSM-2026-4596

GCVE-110-OSM-2026-4596
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published May 22, 2026
[osmalyze-auto] APT malware detected: chai-max. Associated with threat actor(s): DPRK/Lazarus. Behaviors: data exfiltration, code execution, network activity, obfuscated code, install-time execution. [osmalyze-auto] Entrypoint: pubmodules/activities/index.js (default-index: index.js) Exfil: http://developer.tiledesk.com (custom-c2, recovery: plaintext in app.js) Payload: pubmodules/emailNotification/requestNotification.js Secondary files: app.js, .github/workflows/docker-community-worker-push-latest.yml Key findings: - Environment Variable Exfiltration in app.js: "process.env.ENABLE_ALTERNATIVE_CORS_MIDDLEWARE === "true") { app.use(functio..." - Environment Variable Exfiltration in channels/chat21/test-int/chat21Handler.js: "process.env.NODE_ENV = 'test'; require('dotenv').config(); var expect = requir..." - Environment Variable Exfiltration in channels/chat21/test-int/chat21WebHook.js: "process.env.NODE_ENV = 'test'; let mongoose = require("mongoose"); var Request ..." - Environment Variable Exfiltration in models/request.js: "process.env.DEFAULT_FULLTEXT_INDEX_LANGUAGE || "none"; winston.info("Request" - Environment Variable Exfiltration in models/requester.js: "process.env.MONGOOSE_SYNCINDEX) { requester.syncIndexes(); winston.verbose("..." IOCs: - ipv4: 2.3.71.1, 2.3.18.7, 2.3.18.6, 2.3.18.1, 2.1.40.1 (+42 more) - ipv6: BFB:B:B:B:B:B:B:B, 88:: - urls: https://developer.tiledesk.com/, https://YOOURDOMAIN.com/dashboard, https://console.tiledesk.com/v2/dashboard, https://CHANGEIT.cloudfunctions.net, https://CHANGEIT.firebaseio.com (+51 more) - domains: developer.tiledesk.com, tiledesk.com, console.tiledesk.com, CHANGEIT.cloudfunctions.net, CHANGEIT.firebaseapp.com (+28 more) - emails: admin@tiledesk.com, postmaster@mg.tiledesk.com, andrea.leo@f21.it, andrea.leo@frontiere21.it, 5fa26a59-6944-43eb-852a-36850086c357@tiledesk.com (+45 more) - bitcoinAddresses: 1V1Fh8bADsMCUkxkqoc1yiA4SUbH5ajJA, 1SfftUVuynzJu5XV2ur4i6VKVFE, 3da378ec63924bb9b4934b2835b37a7c - webhookServices: https://webhook.site/853e4e5e-18f8-45e6-a366-da0c63470ed6, https://webhook.site/fae496ca-c0a5-4eff-b9aa-53c01585150a, https://webhook.site/bbb5ec7b-1dd2-4b27-8cce-c0fad2b29fe6, https://webhook.site/bd710929-9b43-4065-88db-78ee17f84aec - ips: 216.126.225.129, 169.254.169.254 - paths: /etc/environment, /etc/default/locale, /var/run/secrets/kubernetes.io/serviceaccount/token, /var/run/secrets/kubernetes.io/serviceaccount/ca.crt, /home/runner (+1 more) - payloadFileHash: 23d40276e8c3ebdf8bc7d991041c135128dad0c696b649058596d3361e2497e5 Decoded/deobfuscated IOCs: - urls: http://216.126.225.129:8443?h=megalodon&l=gh_dump&id=hefs8esnhgkx, http://metadata.google.internal/computeMetadata/v1/?recursive=true, http://169.254.169.254/latest/api/token, http://169.254.169.254/latest/meta-data/iam/security-credentials/, http://169.254.169.254/latest/meta-data/iam/security-credentials/$role (+1 more) - ips: 216.126.225.129, 169.254.169.254 - domains: kubernetes.io - paths: /etc/environment, /etc/default/locale, /var/run/secrets/kubernetes.io/serviceaccount/token, /var/run/secrets/kubernetes.io/serviceaccount/ca.crt, /home/runner (+1 more)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@tiledesk/tiledesk-server2.18.12 (affected)

References

advisory
vendor

Browse GCVE Records

74,942 records in the GCVE database · Updated July 27, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›