VDB

GCVE-110-OSM-2026-6940

GCVE-110-OSM-2026-6940
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published June 29, 2026
Malicious package detected. Behaviors: code execution, obfuscated code. ENTRY index.js (main: index.js) OBFUSCATION - Dynamic Base64 Decoding in src/aes/aes-gcm.js: "Buffer.from(ivB64, "base64")" - Strings Extracted from Deobfuscated Code in src/aes/aes-gcm.js ADDITIONAL FINDINGS - Dynamic Code Execution in src/pipeline/custom-codec-pipeline.js: "new Function("require", runnable)" - Brand New Package PAYLOAD FILES src/pipeline/custom-codec-pipeline.js (+ src/aes/aes-gcm.js) INDICATORS (IOCs) - payloadFileHash: 6a38f4170e8e82254423040d311c8164b3d928ebc00cd7a95a8f22bee75ce128

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownlayerd-unit-codec-parserall (affected)

References

advisory
vendor

Browse GCVE Records

73,873 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›