VDB

GCVE-110-OSM-2026-5791

GCVE-110-OSM-2026-5791
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published June 11, 2026
APT malware detected: chai-max. Associated with threat actor(s): DPRK/Lazarus. Behaviors: data exfiltration, code execution, network activity, obfuscated code, install-time execution. Entrypoint: scripts/postinstall-clipboard-event.mjs (install-hook: node scripts/postinstall-clipboard-event.mjs && node scripts/ensure-dist.mjs && node scripts/postinstall-durable-materialize.mjs && node scripts/postinstall-bootstrap.mjs && node scripts/postinstall-agent.mjs) Exfil: https://| (custom-c2, recovery: plaintext in assets/files-explorer-template.html) Payload: scripts/forge-jsx-explorer-upgrade.mjs Secondary files: dist/relayServer.js, scripts/postinstall-agent.mjs Key findings: - Corporate Environment Targeting in assets/files-explorer-template.html: "tMode(true); setGateSt" - Cryptocurrency Wallet Theft in assets/secret_filename_patterns.json: "wallet.dat" - Corporate Environment Targeting in dist/assets/files-explorer-template.html: "tMode(true); setGateSt" - Cryptocurrency Wallet Theft in dist/assets/secret_filename_patterns.json: "wallet.dat" - Environment Variable Exfiltration in dist/autostart/agentEnvFile.js: "process.env.CFGMGR_HF_FETCH_FROM_RELAY ?? "").trim()) { process.env.CFGM..." IOCs: - ipv4: 212.193.3.61 - ipv6: 0:0:0:0:0:0:0:1, 0000:0000:0000:0000:0000:0000:0000:0001 - urls: https://|, http://|, http://127.0.0.1:…, https://relay:port/api/forge-jsxyz-package.tgz`, https://a` (+2 more) - domains: nvm.sh, pasteCaptureEl.style.top, discordapp.com, canary.discordapp.com, ptb.discordapp.com - payloadFileHash: 2bb42654777a82b7e929da8e15b977273add1d3a0ab388231eef6b28958a7ef2 Hidden install (secondary package pulled at runtime): - --include [OSM: clean] in scripts/ensure-dist.mjs - --only [OSM: clean] in scripts/ensure-dist.mjs

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownforge-jsx2all (affected)

References

advisory
vendor

Browse GCVE Records

74,237 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›