VDB

GCVE-110-OSM-2026-5663

GCVE-110-OSM-2026-5663
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published June 11, 2026
This package is a trojanized clone of the popular `events` npm module. The attacker model is a supply-chain implant: a brand-new account (21 days old, single package) publishes a near-name-squat of the ubiquitous `events` module, backdoors the `emit` function to silently forward event data to a bundled obfuscated stager, and iterates rapidly through 5 versions in 3 weeks. The legitimate event-emitter code is present as camouflage around the injected payload. ## C2 infrastructure This package shares campaign C2 infrastructure with other Graphalgo packages confirmed by JFrog Security Research. The campaign C2 chain uses Ethereum Sepolia smart contract `0xE390863Dac96a7118C71227C2b099B50cF602D31` as an encrypted dead-drop, with X25519 ECDH key exchange using hardcoded TA public key `bad013df6eec5d686f4cc8551e0a5c87a0135164bdd1dafb1c75141d1b526702`. Exfiltration uses Slack channel `C0B8XPGCKQS` (bot token embedded in payload) and Telegram chat `-1003952553968` via bot `8961878831`. A second-stage Slack polling agent (channel `C0B8GEPFMK9`) provides persistent remote command execution via AES-GCM/PBKDF2-encrypted operator messages.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownevents-runtimeall (affected), all (affected)

References

advisory
vendor

Browse GCVE Records

346 records in the GCVE database · Updated September 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›