VDB

GCVE-110-OSM-2026-5943

GCVE-110-OSM-2026-5943
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published June 14, 2026
The dist files contain the well-documented sweetalert2 protestware payload verbatim: code that checks `navigator.language` against `/^ru\b/` and `location.host` against `/\.(ru|su|by|xn--p1ai)$/`, then after a 3-day localStorage timer fires `document.body.style.pointerEvents='none'` (full-page sabotage) and dynamically loads audio from `https://flag-gimn.ru/wp-content/uploads/2021/09/Ukraina.mp3` on loop — a deliberate denial-of-service/harassment payload targeting visitors on Russian-TLD sites. This is bundled sweetalert2 v11.11.1 with the protestware intact inside `dist/@sysvale/show.umd.js` and `dist/@sysvale/show.es.js`. The publisher (`@sysvale`) appears legitimate with a long history and zero prior malicious packages, strongly suggesting inadvertent bundling of a tampered sweetalert2 dependency rather than deliberate supply-chain attack by the package author, but the sabotage code is unambiguously present and will execute in production for affected users. The `btoa`/`atob` and string-array findings are false positives from lodash/speakingurl character-map tables bundled alongside. DESTINATION - custom-c2: https://sweetalert2.github.io/#ajax-request` (primary, plaintext) in dist/@sysvale/show.es.js - custom-c2: https://flag-gimn.ru/wp-content/uploads/2021/09/Ukraina.mp3 (plaintext) in dist/@sysvale/show.es.js - custom-c2: https://vee-validate.logaretm.com/v4 (plaintext) in dist/@sysvale/show.es.js - custom-c2: sweetalert2.github.io (plaintext) in dist/@sysvale/show.es.js - custom-c2: flag-gimn.ru (plaintext) in dist/@sysvale/show.es.js - custom-c2: vee-validate.logaretm.com (plaintext) in dist/@sysvale/show.es.js EXFIL - Data Encoding for Exfiltration in dist/@sysvale/show.es.js: "btoa(" - Data Encoding for Exfiltration in dist/@sysvale/show.umd.js: "btoa(" - Dynamic C2 Endpoint Construction in dist/@sysvale/show.umd.js: "function c(){if(y(this,c),S(this,Ii,void 0),!(typeof window>"u")){Rn=this;for(va..." - Data Encoding for Exfiltration in dist/index.5eb888d7.mjs: "encodeURI(r" OBFUSCATION - Dynamic Base64 Decoding in dist/@sysvale/show.es.js: "atob(e)" - Dynamic Base64 Decoding in dist/@sysvale/show.umd.js: "atob(e)" - Unicode Escape Obfuscation in dist/@sysvale/show.es.js: "\xC0\xC1\xC2\xC3\xC4\xC5\xE0\xE1\xE2\xE3\xE4\xE5\xD2\xD3\xD4\xD5\xD5\xD6\xD8\xF2..." - Unicode Escape Obfuscation in dist/@sysvale/show.umd.js: "\u1014\u103A\u102F\u1015\u103A" - Unicode Escape Obfuscation in dist/index.5eb888d7.mjs: "\u1014\u103A\u102F\u1015\u103A" - Obfuscation patterns: stringArrayAccess, unicodeHeavy, hexHeavy in dist/@sysvale/show.es.js - Obfuscation patterns: stringArrayAccess, unicodeHeavy, hexHeavy in dist/@sysvale/show.umd.js - Obfuscation patterns: unicodeHeavy in dist/index.5eb888d7.mjs PAYLOAD FILES dist/@sysvale/show.umd.js (+ dist/@sysvale/show.es.js) INDICATORS (IOCs) - domains: show.es - payloadFileHash: e0f8075809f0373e1291cb26a5639f93269dfcbd88eb690cacd6c6c3b94d0e5b

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@sysvale/show1.24.0 (affected)

References

vendor

Browse GCVE Records

74,267 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›