VDB

GCVE-110-OSM-2026-6025

GCVE-110-OSM-2026-6025
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published June 16, 2026
APT malware detected: chai-max. Associated with threat actor(s): DPRK/Lazarus. Behaviors: data exfiltration, code execution, obfuscated code, install-time execution. ENTRY dist/cli.js (bin: ./dist/cli.js) - Postinstall Script in package.json: ""postinstall": "node -e \"" LOOT - Cryptocurrency Wallet Theft in dist/node/payload.js: "wallet.dat" PERSISTENCE - Startup Persistence in dist/node/payload.js: ".bashrc" DESTINATION - reconstructed: https://huggingface.co/api/repos/create (primary, reconstructed) in dist/node/payload.js - custom-c2: huggingface.co (reconstructed) in dist/node/payload.js - custom-c2: matteocollina.com (plaintext) in dist/node/payload.js - custom-c2: Crypto.com (plaintext) in dist/node/payload.js - custom-c2: 4.0.0.0 (plaintext) in dist/node/payload.js EXFIL - Data Encoding for Exfiltration in dist/node/payload.js: "Buffer.from(opts.auth).toString("base64")" - Git Configuration Access in dist/node/payload.js: ".gitconfig" - Dynamic C2 Endpoint Construction in dist/node/payload.js: ""node.")) { return false; } return true; } function findSystemNode() { var _a; c..." - System Information Collection in dist/node/payload.js: "os.hostname()" - System Information Collection in dist/node/utils.js: "os.homedir()" OBFUSCATION - Dynamic Base64 Decoding in dist/node/payload.js: "atob(base64)" - String Array Obfuscation in dist/node/payload.js: "[ "key", "wallet", "password", "credential", "credentials", "sol", "eth", "tron"..." - recovered 1 urls, 1 domains from decoded/deobfuscated content ADDITIONAL FINDINGS - Download Execute Delete Pattern in dist/node/payload.js: "writeFileSync(jsPath, buffer); logger_js_1.logger.info({ version: remoteVersion ..." - Chai-Max Wallet Theft Indicators in dist/node/payload.js: ".exodus" - Reconstructed Obfuscated URL in dist/node/payload.js: "https://huggingface.co/api/repos/create" - Stealth Background Process Spawning in dist/node/utils.js: "spawn(process.execPath, [script, "--bg"], { detached: true, stdio: "ignore", win..." - Dynamic Code Execution in dist/node/payload.js: "exec(str)" - Shell Command Execution in dist/node/payload.js: "require("child_process")" (+4 more) PAYLOAD FILES dist/node/payload.js INDICATORS (IOCs) - emails: hello@matteocollina.com - payloadFileHash: 8fd99fd596cb9d8ab2bb61ace7fe9048c9f3a78219cb2568a38b10ee53a8a4b2

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownnat-ulidall (affected)

References

advisory
vendor

Browse GCVE Records

75,726 records in the GCVE database · Updated August 1, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›