VDB

GCVE-110-OSM-2026-7649

GCVE-110-OSM-2026-7649
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 10, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code, install-time execution. ENTRY es/index.js (install-hook: node index.js) - Install Hook Executes Local JS File in package.json DESTINATION - deobfuscated: eth.drpc.org (fetched-payload, deobfuscated) - deobfuscated: eth-mainnet.public.blastapi.io (fetched-payload, deobfuscated) - deobfuscated: www.localeplanet.com (fetched-payload, deobfuscated) - deobfuscated: alpha.bn (fetched-payload, deobfuscated) - deobfuscated: alphanumeric.bn (fetched-payload, deobfuscated) - deobfuscated: googlemail.com (fetched-payload, deobfuscated) - deobfuscated: www.brainjar.com (fetched-payload, deobfuscated) - deobfuscated: www.aba.com (fetched-payload, deobfuscated) (+44 more) EXFIL - Data Encoding for Exfiltration in es/lib/isByteLength.js: "encodeURI(str" - Data Encoding for Exfiltration in lib/isByteLength.js: "encodeURI(str" - Data Encoding for Exfiltration in validator.js: "encodeURI(str" OBFUSCATION - IOCs Found in Deobfuscated Code in index.js - IOCs Found in Deobfuscated Code in validator.js - Whitespace-Padded Hidden Payload in index.js: "; global" - Obfuscation: function to array replacements in index.js - Obfuscation: function to array replacements in validator.js - String Array Obfuscation in es/lib/alpha.js: "['bg-BG', 'cs-CZ', 'da-DK', 'de-DE', 'el-GR', 'en-ZM', 'eo', 'es-ES', 'fr-CA', '..." - Unicode Escape Obfuscation in es/lib/alpha.js: "\u04D8\u04B0\u0406\u04A2\u0492\u04AE\u049A\u04E8\u04BA" - String Array Obfuscation in es/lib/isISO15924.js: "['Adlm', 'Afak', 'Aghb', 'Ahom', 'Arab', 'Aran', 'Armi', 'Armn', 'Avst', 'Bali',..." (+26 more) ADDITIONAL FINDINGS - XOR-Encoded String Arrays in es/lib/isTaxID.js: "var multip_lookup = [2, 4, 8, 5, 10, 9, 7, 3, 6]" - Dynamic Code Execution in es/lib/util/typeOf.js: "exec(rawObject)" PAYLOAD FILES validator.js (+ index.js) INDICATORS (IOCs) - ipv4: 3.1.1.1, 3.1.1.5 - ipv6: fe80::, ff02::, ff08:: - urls: https://gitter.im/validatorjs/community, http://requirejs.org/docs/whyamd.html, http://bower.io/, http://www.crockford.com/base32.html, https://base64.guru/standards/base64url (+30 more) - domains: bar.com, gitter.im, badges.gitter.im, huntr.dev, requirejs.org (+5 more) - emails: foo@bar.com - payloadFileHash: 6752b23ec1c7e5c3cb7ca7290367988bd51d6359e156fcb32da373edc0955ce1

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownvalidator-stringall (affected)

References

advisory
vendor

Browse GCVE Records

74,198 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›