VDB
GCVE-110-OSM-2026-5890
GCVE-110-OSM-2026-5890
Advisory PublishedCVSS 9.6/10
This package is a social engineering lure targeting job-seeking developers. The entrypoint (bin/index.js) executes a fully fabricated 'analysis' that simulates a progress bar, then displays alarming fake code-quality failures designed to frighten the user, and finally directs them to https://interviewgenie.icu/calibrate — a freshly registered .icu domain with no legitimate pedigree — under false urgency with a bypass code ('URGENT50'). The goal is to drive the victim to an attacker-controlled site, likely for credential phishing or malware delivery. Compounding this, the package's chalk dependency is flagged as a known-malicious variant, suggesting the trojanized dependency may carry the real payload while the entrypoint script handles the social engineering pretext. The publisher account is 96 hours old, has no prior history, and the other four published packages are near-exact typosquats of popular libraries (framer-motion-core, react-query-utils, react-router-dom-utils, tailwindcss-core), indicating a coordinated campaign rather than an isolated bad package.
ENTRY
bin/index.js (bin: ./bin/index.js)
ADDITIONAL FINDINGS
- Suspicious TLD Domain in bin/index.js: "https://interviewgenie.icu"
- Malicious Dependency Detected in package.json
PAYLOAD FILES
bin/index.js
INDICATORS (IOCs)
- urls: https://interviewgenie.icu/calibrate
- domains: interviewgenie.icu
- payloadFileHash: 9f530112750a4403fc1a34cd00fcdd96f1223987324d72a76bfd3cda5ff7bae5
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | faang-analyzer | all (affected) | — |
Browse GCVE Records
73,873 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.