VDB
GCVE-110-OSM-2026-7649
GCVE-110-OSM-2026-7649
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code, install-time execution.
ENTRY
es/index.js (install-hook: node index.js)
- Install Hook Executes Local JS File in package.json
DESTINATION
- deobfuscated: eth.drpc.org (fetched-payload, deobfuscated)
- deobfuscated: eth-mainnet.public.blastapi.io (fetched-payload, deobfuscated)
- deobfuscated: www.localeplanet.com (fetched-payload, deobfuscated)
- deobfuscated: alpha.bn (fetched-payload, deobfuscated)
- deobfuscated: alphanumeric.bn (fetched-payload, deobfuscated)
- deobfuscated: googlemail.com (fetched-payload, deobfuscated)
- deobfuscated: www.brainjar.com (fetched-payload, deobfuscated)
- deobfuscated: www.aba.com (fetched-payload, deobfuscated)
(+44 more)
EXFIL
- Data Encoding for Exfiltration in es/lib/isByteLength.js: "encodeURI(str"
- Data Encoding for Exfiltration in lib/isByteLength.js: "encodeURI(str"
- Data Encoding for Exfiltration in validator.js: "encodeURI(str"
OBFUSCATION
- IOCs Found in Deobfuscated Code in index.js
- IOCs Found in Deobfuscated Code in validator.js
- Whitespace-Padded Hidden Payload in index.js: "; global"
- Obfuscation: function to array replacements in index.js
- Obfuscation: function to array replacements in validator.js
- String Array Obfuscation in es/lib/alpha.js: "['bg-BG', 'cs-CZ', 'da-DK', 'de-DE', 'el-GR', 'en-ZM', 'eo', 'es-ES', 'fr-CA', '..."
- Unicode Escape Obfuscation in es/lib/alpha.js: "\u04D8\u04B0\u0406\u04A2\u0492\u04AE\u049A\u04E8\u04BA"
- String Array Obfuscation in es/lib/isISO15924.js: "['Adlm', 'Afak', 'Aghb', 'Ahom', 'Arab', 'Aran', 'Armi', 'Armn', 'Avst', 'Bali',..."
(+26 more)
ADDITIONAL FINDINGS
- XOR-Encoded String Arrays in es/lib/isTaxID.js: "var multip_lookup = [2, 4, 8, 5, 10, 9, 7, 3, 6]"
- Dynamic Code Execution in es/lib/util/typeOf.js: "exec(rawObject)"
PAYLOAD FILES
validator.js (+ index.js)
INDICATORS (IOCs)
- ipv4: 3.1.1.1, 3.1.1.5
- ipv6: fe80::, ff02::, ff08::
- urls: https://gitter.im/validatorjs/community, http://requirejs.org/docs/whyamd.html, http://bower.io/, http://www.crockford.com/base32.html, https://base64.guru/standards/base64url (+30 more)
- domains: bar.com, gitter.im, badges.gitter.im, huntr.dev, requirejs.org (+5 more)
- emails: foo@bar.com
- payloadFileHash: 6752b23ec1c7e5c3cb7ca7290367988bd51d6359e156fcb32da373edc0955ce1
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | validator-string | all (affected) | — |
Aliases
Browse GCVE Records
74,198 records in the GCVE database · Updated July 21, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.