VDB
GCVE-110-OSM-2026-6025
GCVE-110-OSM-2026-6025
Advisory PublishedCVSS 9.6/10
APT malware detected: chai-max. Associated with threat actor(s): DPRK/Lazarus. Behaviors: data exfiltration, code execution, obfuscated code, install-time execution.
ENTRY
dist/cli.js (bin: ./dist/cli.js)
- Postinstall Script in package.json: ""postinstall": "node -e \""
LOOT
- Cryptocurrency Wallet Theft in dist/node/payload.js: "wallet.dat"
PERSISTENCE
- Startup Persistence in dist/node/payload.js: ".bashrc"
DESTINATION
- reconstructed: https://huggingface.co/api/repos/create (primary, reconstructed) in dist/node/payload.js
- custom-c2: huggingface.co (reconstructed) in dist/node/payload.js
- custom-c2: matteocollina.com (plaintext) in dist/node/payload.js
- custom-c2: Crypto.com (plaintext) in dist/node/payload.js
- custom-c2: 4.0.0.0 (plaintext) in dist/node/payload.js
EXFIL
- Data Encoding for Exfiltration in dist/node/payload.js: "Buffer.from(opts.auth).toString("base64")"
- Git Configuration Access in dist/node/payload.js: ".gitconfig"
- Dynamic C2 Endpoint Construction in dist/node/payload.js: ""node.")) { return false; } return true; } function findSystemNode() { var _a; c..."
- System Information Collection in dist/node/payload.js: "os.hostname()"
- System Information Collection in dist/node/utils.js: "os.homedir()"
OBFUSCATION
- Dynamic Base64 Decoding in dist/node/payload.js: "atob(base64)"
- String Array Obfuscation in dist/node/payload.js: "[ "key", "wallet", "password", "credential", "credentials", "sol", "eth", "tron"..."
- recovered 1 urls, 1 domains from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Download Execute Delete Pattern in dist/node/payload.js: "writeFileSync(jsPath, buffer); logger_js_1.logger.info({ version: remoteVersion ..."
- Chai-Max Wallet Theft Indicators in dist/node/payload.js: ".exodus"
- Reconstructed Obfuscated URL in dist/node/payload.js: "https://huggingface.co/api/repos/create"
- Stealth Background Process Spawning in dist/node/utils.js: "spawn(process.execPath, [script, "--bg"], { detached: true, stdio: "ignore", win..."
- Dynamic Code Execution in dist/node/payload.js: "exec(str)"
- Shell Command Execution in dist/node/payload.js: "require("child_process")"
(+4 more)
PAYLOAD FILES
dist/node/payload.js
INDICATORS (IOCs)
- emails: hello@matteocollina.com
- payloadFileHash: 8fd99fd596cb9d8ab2bb61ace7fe9048c9f3a78219cb2568a38b10ee53a8a4b2
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | nat-ulid | all (affected) | — |
Aliases
Browse GCVE Records
75,726 records in the GCVE database · Updated August 1, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.