VDB
GCVE-110-OSM-2026-5683
GCVE-110-OSM-2026-5683
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code.
Entrypoint: cli/main.cjs (bin: cli/main.cjs)
Exfil: https://cdn.builder.io/api/v1/snippet/"//http://localhost:3000" (reconstructed, recovery: reconstructed in cli/index.cjs)
Loader: https://docs.google.com/forms/d/e/1FAIpQLSdqZcJpRtm_Ia5DTHP6SDY9Xa6LID3KiTjRWkjMzWyJRUtSHw/viewform in cli/index.cjs
Payload: cli/index.cjs
Secondary files: server/index.cjs, server/index.mjs
Key findings:
- Environment Variable Exfiltration in cli/index.cjs: "process.env.${Ja}${n?"!":""};
${n?G9(t):""}
export default async function Page..."
- Sensitive File Access in cli/index.cjs: ""~/.npmrc""
- Corporate Environment Targeting in cli/index.cjs: "tModeReservedWord(w.name)&&this.tolerateUnexpectedToken(f,s.Messages.StrictReser..."
- Cryptocurrency Wallet Theft in cli/index.cjs: "wallet.dat"
- Browser Data Theft in cli/index.cjs: "firefox/i],[m,[u,ce+" Reality"]],[/ekiohf.+(flow)\\/([\\w\\.]+)/i,/(swiftfox)/i,..."
IOCs:
- ipv4: 1.1.1.1
- ipv6: fe80::, fc00::, f::, 3344::, 88::
- urls: https://nextjs.org/docs/app/api-reference/next-config-js, https://remix.run/docs/en/main/file-conventions/remix-config, https://webpack.js.org/configuration/plugins/, https://docs.google.com/forms/d/e/1FAIpQLSdqZcJpRtm_Ia5DTHP6SDY9Xa6LID3KiTjRWkjMzWyJRUtSHw/viewform, https://www.figma.com/community/plugin/747985167520967365/builder-io-ai-powered-figma-to-code-react-vue-tailwind-more (+47 more)
- domains: nextjs.org, webpack.js.org, k.format.space, s.global, this.global (+17 more)
- emails: key_1234@dotenv.org, i@maskray.me
- bitcoinAddresses: 38af5e1d956b48c29e1199757cc72fdb, 1df91c56b25955c56387426f378173c5, 3e767a3cecc8712b72871c2526ec5abe, 12aa52f7e7163e1e37b3b16ddd7e267d, 3e57a4cd3267159f3772bebd73534451 (+22 more)
- sha256Hashes: 77fa9d1570a153d1f6171e29d4650f05b4ee7f28f09e94bb10c40108f1237d3c, 183613c2acd7df7fb88682c42deef5e84d8522e6a384f4ad19327df1bda5dfab
- _domainCandidates: t.scripts.dev, r.space, r.scripts.dev
- payloadFileHash: 5b3d93ceed79b9330025b7ce7dbed3973323d544a11dcbcce1c1733320a243cf
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @builder.io/dev-tools | 1.65.0 (affected) | — |
Aliases
Browse GCVE Records
74,352 records in the GCVE database · Updated July 22, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.