VDB

GCVE-110-OSM-2026-5683

GCVE-110-OSM-2026-5683
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published June 11, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code. Entrypoint: cli/main.cjs (bin: cli/main.cjs) Exfil: https://cdn.builder.io/api/v1/snippet/"//http://localhost:3000" (reconstructed, recovery: reconstructed in cli/index.cjs) Loader: https://docs.google.com/forms/d/e/1FAIpQLSdqZcJpRtm_Ia5DTHP6SDY9Xa6LID3KiTjRWkjMzWyJRUtSHw/viewform in cli/index.cjs Payload: cli/index.cjs Secondary files: server/index.cjs, server/index.mjs Key findings: - Environment Variable Exfiltration in cli/index.cjs: "process.env.${Ja}${n?"!":""}; ${n?G9(t):""} export default async function Page..." - Sensitive File Access in cli/index.cjs: ""~/.npmrc"" - Corporate Environment Targeting in cli/index.cjs: "tModeReservedWord(w.name)&&this.tolerateUnexpectedToken(f,s.Messages.StrictReser..." - Cryptocurrency Wallet Theft in cli/index.cjs: "wallet.dat" - Browser Data Theft in cli/index.cjs: "firefox/i],[m,[u,ce+" Reality"]],[/ekiohf.+(flow)\\/([\\w\\.]+)/i,/(swiftfox)/i,..." IOCs: - ipv4: 1.1.1.1 - ipv6: fe80::, fc00::, f::, 3344::, 88:: - urls: https://nextjs.org/docs/app/api-reference/next-config-js, https://remix.run/docs/en/main/file-conventions/remix-config, https://webpack.js.org/configuration/plugins/, https://docs.google.com/forms/d/e/1FAIpQLSdqZcJpRtm_Ia5DTHP6SDY9Xa6LID3KiTjRWkjMzWyJRUtSHw/viewform, https://www.figma.com/community/plugin/747985167520967365/builder-io-ai-powered-figma-to-code-react-vue-tailwind-more (+47 more) - domains: nextjs.org, webpack.js.org, k.format.space, s.global, this.global (+17 more) - emails: key_1234@dotenv.org, i@maskray.me - bitcoinAddresses: 38af5e1d956b48c29e1199757cc72fdb, 1df91c56b25955c56387426f378173c5, 3e767a3cecc8712b72871c2526ec5abe, 12aa52f7e7163e1e37b3b16ddd7e267d, 3e57a4cd3267159f3772bebd73534451 (+22 more) - sha256Hashes: 77fa9d1570a153d1f6171e29d4650f05b4ee7f28f09e94bb10c40108f1237d3c, 183613c2acd7df7fb88682c42deef5e84d8522e6a384f4ad19327df1bda5dfab - _domainCandidates: t.scripts.dev, r.space, r.scripts.dev - payloadFileHash: 5b3d93ceed79b9330025b7ce7dbed3973323d544a11dcbcce1c1733320a243cf

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@builder.io/dev-tools1.65.0 (affected)

References

advisory
vendor

Browse GCVE Records

74,352 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›