VDB
GCVE-110-OSM-2026-7885
GCVE-110-OSM-2026-7885
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code.
ENTRY
index.js (main: index.js)
DESTINATION
- custom-c2: https://jsonhosting.com/api/json/e16583b1/raw (primary, deobfuscated) in lib/caller.js
- custom-c2: https://jsonkeeper.com/b/XRGF3 (decoded) in lib/caller.js
- custom-c2: https://jsonkeeper.com/b/4NAKK (decoded) in lib/caller.js
- custom-c2: jsonhosting.com (deobfuscated) in lib/caller.js
- custom-c2: jsonkeeper.com (decoded) in lib/caller.js
EXFIL
- Network Request in lib/caller.js: "axios.get("
OBFUSCATION
- Global Variable Shadowing in lib/caller.js: "const process = {"
- Decoded Base64 Content in lib/caller.js
- Decoded Base64 Content in lib/const.js
- Decoded Base64 Content in [deobfuscated] lib/caller.js
- IOCs Found in Deobfuscated Code in lib/caller.js
- recovered 3 urls, 2 domains, 1 _domainCandidates from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Stealth Background Process Spawning in index.js: "spawn("node", [script, JSON.stringify(args)], { detached: true, stdio: "ignore" ..."
- Shell Command Execution in index.js: "require("child_process")"
- Silent Process Execution in index.js: "stdio: "ignore""
- Detached Child Process Payload in index.js: "spawn("node", [script, JSON.stringify(args)], { detached: true"
- Dynamic Code Execution in lib/caller.js: "Function.constructor("
PAYLOAD FILES
lib/caller.js
INDICATORS (IOCs)
- urls: http://192.168.1.42:9200
- payloadFileHash: 445a65314361697cc4c43f798bd333b5c2d91e39f4ce44af4d436328dad82427
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | type-swap | all (affected) | — |
Aliases
Browse GCVE Records
75,875 records in the GCVE database · Updated August 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.