VDB

GCVE-110-OSM-2026-7888

GCVE-110-OSM-2026-7888
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 13, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code. ENTRY dist/core/compaction/index.js (default-index: index.js) PERSISTENCE - Startup Persistence in dist/modes/interactive/theme/theme.js: "startup/" DESTINATION - reconstructed: https://github.com/earendil-works/pi (primary, reconstructed) in CHANGELOG.md - urls: https://pi.dev (c2, plaintext) - domains: pi.dev (c2, plaintext) - domains: github.com (c2, plaintext) EXFIL - Environment Variable Exfiltration in dist/cli.js: "process.env.PI_CODING_AGENT = "true"; process.emitWarning = (() => { }); // Conf..." - Corporate Environment Targeting in dist/core/model-resolver.d.ts: "tModelReferenceMatch" - Corporate Environment Targeting in dist/core/model-resolver.js: "tModelReferenceMatch" - Environment Variable Exfiltration in dist/core/telemetry-sync.js: "process.env.QUICKCALL_DEVICE_ID || undefined, org: process.env.QUICKCALL_ORG || ..." - Corporate Environment Targeting in dist/modes/interactive/components/model-selector.d.ts: "tModels; private getScopeText; private getScopeHintText; private setScope; priva..." - Corporate Environment Targeting in dist/modes/interactive/components/model-selector.js: "tModel, item.model)); this.selectedIndex = currentIndex >= 0 ? currentIndex : 0;..." - Corporate Environment Targeting in dist/modes/interactive/components/session-selector-search.d.ts: "tMode = "threaded" | "recent" | "relevance"; export type NameFilter" - Corporate Environment Targeting in dist/modes/interactive/components/session-selector-search.js: "tMode, nameFilter = "all") { const nameFiltered = nameFilter === "all" ? session..." (+40 more) OBFUSCATION - Dynamic Base64 Decoding in dist/core/export-html/template.js: "atob(base64)" - Dynamic Base64 Decoding in dist/utils/image-convert.js: "Buffer.from(base64Data, "base64")" - Unicode Escape Obfuscation in dist/core/tools/edit-diff.js: "\u2010\u2011\u2012\u2013\u2014\u2015\u2212" - Base64 Encoded Payload in dist/modes/interactive/components/daxnuts.js: ""bbbab8b9b9b6b9b8b5bcbbb8b8b7b4b7b5b2b6b5b2b8b7b4b7b6b3b6b4b1bdbcb8bab8b6bbb8b5b..." - String Array Obfuscation in dist/modes/interactive/theme/theme-schema.json: "[ "accent", "border", "borderAccent", "borderMuted", "success", "error", "warnin..." - Decoded Base64 Content in examples/extensions/custom-provider-anthropic/index.ts - Deobfuscation Failed in dist/core/export-html/template.js - Deobfuscation Failed in dist/utils/image-convert.js (+1 more) ADDITIONAL FINDINGS - Download Execute Delete Pattern in dist/modes/interactive/components/session-selector.js: "spawnSync } from "node:child_process"; import { existsSync } from "node:fs"; imp..." - Reconstructed Obfuscated URL in dist/utils/changelog.js: "https://github.com/earendil-works/pi" - Dynamic Code Execution in dist/core/export-html/ansi-to-html.js: "exec(text)" - Clipboard Access in dist/core/export-html/template.js: "navigator.clipboard.writeText" - Shell Command Execution in dist/core/footer-data-provider.js: "spawnSync(" - Silent Process Execution in dist/core/resolve-config-value.js: "windowsHide: true" (+1 more) PAYLOAD FILES dist/modes/interactive/interactive-mode.js (+ dist/core/telemetry-sync.js, dist/modes/interactive/components/session-selector.js) INDICATORS (IOCs) - ipv6: 8::, 2::, 22::, 6::, 7:: (+1 more) - urls: https://platform.xiaomimimo.com, https://pi.dev`, https://pi.dev/install?version=x.y.z`, https://pi.dev/install?version=0.67.1`., https://` (+44 more) - domains: platform.xiaomimimo.com, exe.dev, deepseek.com, agentskills.io, models.dev (+30 more) - sha256Hashes: da4edff2e6ebd2bc3208611e2768bc1c1dd7be791dc5ff26ca34ca9ee44f7d4b - payloadFileHash: 7c852cd57aa69709a8e9bf782410321d714a9d8fbee395ea6b3fbb424eaaa91d

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@quickcall/krew0.1.11 (affected)

References

advisory
vendor

Browse GCVE Records

75,797 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›