VDB
GCVE-110-OSM-2026-54
GCVE-110-OSM-2026-54
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code, install-time execution.
Entrypoint: prepinstall.js (install-hook: node ./prepinstall.js)
Exfil: https://jsonkeeper.com/b/DWNFF (custom-c2, recovery: decoded in prepinstall.js)
Payload: prepinstall.js
Secondary files: [deobfuscated] prepinstall.js
Key findings:
- Decoded Base64 Content in prepinstall.js
- Decoded Base64 Content in [deobfuscated] prepinstall.js
- Install Hook Executes Local JS File in package.json: ""postinstall": "node ./prepinstall.js""
- Shell Command Execution in prepinstall.js: "require('child_process')"
- Dynamic Base64 Decoding in prepinstall.js: "atob(HASH_KEY)"
IOCs:
- urls: http://unlicense.org/, https://val.codejam.info/, https://jsonkeeper.com/b/DWNFF
- domains: unlicense.org, val.codejam.info, jsonkeeper.com
- payloadFileHash: e7c772a541f61ef9cd7b77f1d6f2d216faa593b0348cf76f483df6ea873c2335
Decoded/deobfuscated IOCs:
- urls: https://jsonkeeper.com/b/DWNFF
- domains: jsonkeeper.com
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | kyxhiagent | all (affected), * (affected), all (affected), * (affected), all (affected), all (affected), all (affected), * (affected) | — |
| unknown | chai-as-emitted | all (affected), all (affected), all (affected), all (affected), all (affected), * (affected) | — |
| unknown | crypto-promise-js | 1.0.2 (affected) | — |
| unknown | express-session-vailidator | all (affected) | — |
References
Malicious npm package: kyxhiagent
advisory
Browse GCVE Records
74,608 records in the GCVE database · Updated July 24, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.