VDB
GCVE-110-OSM-2026-7240
GCVE-110-OSM-2026-7240
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution.
ENTRY
dist/node/axios.cjs (main: ./dist/node/axios.cjs)
DESTINATION
- custom-c2: http://[::ffff:192.168.1.5 (primary, plaintext) in dist/node/axios.cjs
- custom-c2: 40email.com (plaintext) in dist/node/axios.cjs
- custom-c2: 0:0:0:0:0:0:0:1 (plaintext) in dist/node/axios.cjs
EXFIL
- Data Encoding for Exfiltration in dist/axios.js: "btoa("
- Data Encoding for Exfiltration in dist/browser/axios.cjs: "btoa("
- Data Encoding for Exfiltration in dist/esm/axios.js: "btoa("
- Data Encoding for Exfiltration in dist/node/axios.cjs: "Buffer.from(proxyAuth, 'utf8').toString('base64')"
- Data Encoding for Exfiltration in lib/adapters/http.js: "Buffer.from(proxyAuth, 'utf8').toString('base64')"
- Data Encoding for Exfiltration in lib/helpers/AxiosURLSearchParams.js: "encodeURIComponent(str).replace(/[!'()~]|%20/g, function replacer(match"
- Data Encoding for Exfiltration in lib/helpers/buildURL.js: "encodeURIComponent(val"
- Data Encoding for Exfiltration in lib/helpers/cookies.js: "encodeURIComponent(value"
(+3 more)
ADDITIONAL FINDINGS
- Publisher Has Other Malicious Packages
- Dynamic Code Execution in dist/axios.js: "exec(str)"
PAYLOAD FILES
dist/node/axios.cjs (+ dist/axios.js, dist/browser/axios.cjs)
INDICATORS (IOCs)
- urls: https://user:p%40ss@host`, https://axios-http.com/, https://stytch.com/, https://stytch.com, https://axios.rest (+27 more)
- domains: axios-http.com, thanks.dev, Thanks.dev, www.principal.com, principal.com (+32 more)
- payloadFileHash: d4c10e2138fcf1d62b47d6cfe02bc72e669d75681b42f2bf80e27beabf7f86b9
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | axiosqqq | all (affected) | — |
Aliases
Browse GCVE Records
74,299 records in the GCVE database · Updated July 22, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.