VDB
GCVE-110-OSM-2026-4596
GCVE-110-OSM-2026-4596
Advisory PublishedCVSS 9.6/10
[osmalyze-auto] APT malware detected: chai-max. Associated with threat actor(s): DPRK/Lazarus. Behaviors: data exfiltration, code execution, network activity, obfuscated code, install-time execution.
[osmalyze-auto] Entrypoint: pubmodules/activities/index.js (default-index: index.js)
Exfil: http://developer.tiledesk.com (custom-c2, recovery: plaintext in app.js)
Payload: pubmodules/emailNotification/requestNotification.js
Secondary files: app.js, .github/workflows/docker-community-worker-push-latest.yml
Key findings:
- Environment Variable Exfiltration in app.js: "process.env.ENABLE_ALTERNATIVE_CORS_MIDDLEWARE === "true") {
app.use(functio..."
- Environment Variable Exfiltration in channels/chat21/test-int/chat21Handler.js: "process.env.NODE_ENV = 'test';
require('dotenv').config();
var expect = requir..."
- Environment Variable Exfiltration in channels/chat21/test-int/chat21WebHook.js: "process.env.NODE_ENV = 'test';
let mongoose = require("mongoose");
var Request ..."
- Environment Variable Exfiltration in models/request.js: "process.env.DEFAULT_FULLTEXT_INDEX_LANGUAGE || "none";
winston.info("Request"
- Environment Variable Exfiltration in models/requester.js: "process.env.MONGOOSE_SYNCINDEX) {
requester.syncIndexes();
winston.verbose("..."
IOCs:
- ipv4: 2.3.71.1, 2.3.18.7, 2.3.18.6, 2.3.18.1, 2.1.40.1 (+42 more)
- ipv6: BFB:B:B:B:B:B:B:B, 88::
- urls: https://developer.tiledesk.com/, https://YOOURDOMAIN.com/dashboard, https://console.tiledesk.com/v2/dashboard, https://CHANGEIT.cloudfunctions.net, https://CHANGEIT.firebaseio.com (+51 more)
- domains: developer.tiledesk.com, tiledesk.com, console.tiledesk.com, CHANGEIT.cloudfunctions.net, CHANGEIT.firebaseapp.com (+28 more)
- emails: admin@tiledesk.com, postmaster@mg.tiledesk.com, andrea.leo@f21.it, andrea.leo@frontiere21.it, 5fa26a59-6944-43eb-852a-36850086c357@tiledesk.com (+45 more)
- bitcoinAddresses: 1V1Fh8bADsMCUkxkqoc1yiA4SUbH5ajJA, 1SfftUVuynzJu5XV2ur4i6VKVFE, 3da378ec63924bb9b4934b2835b37a7c
- webhookServices: https://webhook.site/853e4e5e-18f8-45e6-a366-da0c63470ed6, https://webhook.site/fae496ca-c0a5-4eff-b9aa-53c01585150a, https://webhook.site/bbb5ec7b-1dd2-4b27-8cce-c0fad2b29fe6, https://webhook.site/bd710929-9b43-4065-88db-78ee17f84aec
- ips: 216.126.225.129, 169.254.169.254
- paths: /etc/environment, /etc/default/locale, /var/run/secrets/kubernetes.io/serviceaccount/token, /var/run/secrets/kubernetes.io/serviceaccount/ca.crt, /home/runner (+1 more)
- payloadFileHash: 23d40276e8c3ebdf8bc7d991041c135128dad0c696b649058596d3361e2497e5
Decoded/deobfuscated IOCs:
- urls: http://216.126.225.129:8443?h=megalodon&l=gh_dump&id=hefs8esnhgkx, http://metadata.google.internal/computeMetadata/v1/?recursive=true, http://169.254.169.254/latest/api/token, http://169.254.169.254/latest/meta-data/iam/security-credentials/, http://169.254.169.254/latest/meta-data/iam/security-credentials/$role (+1 more)
- ips: 216.126.225.129, 169.254.169.254
- domains: kubernetes.io
- paths: /etc/environment, /etc/default/locale, /var/run/secrets/kubernetes.io/serviceaccount/token, /var/run/secrets/kubernetes.io/serviceaccount/ca.crt, /home/runner (+1 more)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @tiledesk/tiledesk-server | 2.18.12 (affected) | — |
Aliases
Browse GCVE Records
74,942 records in the GCVE database · Updated July 27, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.