VDB
GCVE-110-OSM-2026-5943
GCVE-110-OSM-2026-5943
Advisory PublishedCVSS 9.6/10
The dist files contain the well-documented sweetalert2 protestware payload verbatim: code that checks `navigator.language` against `/^ru\b/` and `location.host` against `/\.(ru|su|by|xn--p1ai)$/`, then after a 3-day localStorage timer fires `document.body.style.pointerEvents='none'` (full-page sabotage) and dynamically loads audio from `https://flag-gimn.ru/wp-content/uploads/2021/09/Ukraina.mp3` on loop — a deliberate denial-of-service/harassment payload targeting visitors on Russian-TLD sites. This is bundled sweetalert2 v11.11.1 with the protestware intact inside `dist/@sysvale/show.umd.js` and `dist/@sysvale/show.es.js`. The publisher (`@sysvale`) appears legitimate with a long history and zero prior malicious packages, strongly suggesting inadvertent bundling of a tampered sweetalert2 dependency rather than deliberate supply-chain attack by the package author, but the sabotage code is unambiguously present and will execute in production for affected users. The `btoa`/`atob` and string-array findings are false positives from lodash/speakingurl character-map tables bundled alongside.
DESTINATION
- custom-c2: https://sweetalert2.github.io/#ajax-request` (primary, plaintext) in dist/@sysvale/show.es.js
- custom-c2: https://flag-gimn.ru/wp-content/uploads/2021/09/Ukraina.mp3 (plaintext) in dist/@sysvale/show.es.js
- custom-c2: https://vee-validate.logaretm.com/v4 (plaintext) in dist/@sysvale/show.es.js
- custom-c2: sweetalert2.github.io (plaintext) in dist/@sysvale/show.es.js
- custom-c2: flag-gimn.ru (plaintext) in dist/@sysvale/show.es.js
- custom-c2: vee-validate.logaretm.com (plaintext) in dist/@sysvale/show.es.js
EXFIL
- Data Encoding for Exfiltration in dist/@sysvale/show.es.js: "btoa("
- Data Encoding for Exfiltration in dist/@sysvale/show.umd.js: "btoa("
- Dynamic C2 Endpoint Construction in dist/@sysvale/show.umd.js: "function c(){if(y(this,c),S(this,Ii,void 0),!(typeof window>"u")){Rn=this;for(va..."
- Data Encoding for Exfiltration in dist/index.5eb888d7.mjs: "encodeURI(r"
OBFUSCATION
- Dynamic Base64 Decoding in dist/@sysvale/show.es.js: "atob(e)"
- Dynamic Base64 Decoding in dist/@sysvale/show.umd.js: "atob(e)"
- Unicode Escape Obfuscation in dist/@sysvale/show.es.js: "\xC0\xC1\xC2\xC3\xC4\xC5\xE0\xE1\xE2\xE3\xE4\xE5\xD2\xD3\xD4\xD5\xD5\xD6\xD8\xF2..."
- Unicode Escape Obfuscation in dist/@sysvale/show.umd.js: "\u1014\u103A\u102F\u1015\u103A"
- Unicode Escape Obfuscation in dist/index.5eb888d7.mjs: "\u1014\u103A\u102F\u1015\u103A"
- Obfuscation patterns: stringArrayAccess, unicodeHeavy, hexHeavy in dist/@sysvale/show.es.js
- Obfuscation patterns: stringArrayAccess, unicodeHeavy, hexHeavy in dist/@sysvale/show.umd.js
- Obfuscation patterns: unicodeHeavy in dist/index.5eb888d7.mjs
PAYLOAD FILES
dist/@sysvale/show.umd.js (+ dist/@sysvale/show.es.js)
INDICATORS (IOCs)
- domains: show.es
- payloadFileHash: e0f8075809f0373e1291cb26a5639f93269dfcbd88eb690cacd6c6c3b94d0e5b
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @sysvale/show | 1.24.0 (affected) | — |
Browse GCVE Records
74,267 records in the GCVE database · Updated July 22, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.