VDB

GCVE-110-OSM-2026-6407

GCVE-110-OSM-2026-6407
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published June 19, 2026
Malicious package detected. Behaviors: data exfiltration. ENTRY index.js (main: index.js) DESTINATION - custom-c2: https://www.jsonkeeper.com/b/XVHGD (primary, decoded) in helpers.js - custom-c2: www.jsonkeeper.com (decoded) in helpers.js EXFIL - Data Encoding for Exfiltration in helpers.js: "btoa(" OBFUSCATION - Decoded Base64 Content in helpers.js - recovered 1 urls, 1 domains from decoded/deobfuscated content ADDITIONAL FINDINGS - Brand New Package PAYLOAD FILES helpers.js INDICATORS (IOCs) - emails: adam@reis.nz - payloadFileHash: ab1f950a7918cde73fc8e6eccdbfd4ecb142c9853bdc4fa39f6232e69e7d6bcc

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownmongoose-json-format3.0.0 (affected)

Browse GCVE Records

74,557 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›