VDB

GCVE-110-OSM-2026-6257

GCVE-110-OSM-2026-6257
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published June 18, 2026
Suspected dependency confusion attack. Behaviors: code execution, obfuscated code. ENTRY index.html (main: index.html) DESTINATION - domains: store.steampowered.com (c2, plaintext) OBFUSCATION - Unicode Escape Obfuscation in assets/index.f76e9af4.js: "\u8BB0\u5F55\u641C\u7D22\u3001\u4E0B\u8F7D\u3001\u89E3\u538B\u548C\u672C\u5730\u..." - Obfuscation patterns: unicodeHeavy in assets/index.f76e9af4.js ADDITIONAL FINDINGS - Download Execute Delete Pattern in assets/index.f76e9af4.js: "Executable); } } return null; } function cleanupTemp(targetPath) { const mayfly ..." - Shell Command Execution in preload.js: "require('child_process')" - Silent Process Execution in preload.js: "stdio: 'ignore'" - Publisher Has Other Malicious Packages PAYLOAD FILES assets/index.f76e9af4.js (+ preload.js) INDICATORS (IOCs) - ipv4: 124.0.0.0, 12.22.37.31, 24.25.42.5 - urls: https://archive.flingtrainer.com/, https://flingtrainer.com/all-trainers-a-z/ - domains: archive.flingtrainer.com, flingtrainer.com, n.group, cdn.akamai.steamstatic.com - payloadFileHash: 67fbc22c87fb19b75c5bf65c55ff7b92352e8bf8d00c51ac303dec951b327b4e

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownmayfly-game-trainerall (affected)

References

vendor

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›