VDB
GCVE-110-OSM-2026-7904
GCVE-110-OSM-2026-7904
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code.
ENTRY
index.html (main: index.html)
PERSISTENCE
- Startup Persistence in assets/livekit-C0E_jLSz.js: ".profile"
- Startup Persistence in assets/react-CKawGOZZ.js: ".profile"
DESTINATION
- reconstructed: https://m1.openfpcdn.io/fingerprintjs/v5.2.0/npm-monitoring (primary, reconstructed) in assets/fingerprint-Y5nV5FVa.js
- reconstructed: https://github.com/syntax-tree/hast-util-to-jsx-runtime#cannot-parse-style-attribute (reconstructed) in assets/fingerprint-Y5nV5FVa.js
- reconstructed: https://65536:65536 (reconstructed) in assets/fingerprint-Y5nV5FVa.js
- reconstructed: https://react.dev/errors/null (reconstructed) in assets/fingerprint-Y5nV5FVa.js
- custom-c2: 21baseballacademy.com (deobfuscated) in assets/boot-CVPGRFHh.js
- custom-c2: react.dev (reconstructed) in assets/react-CKawGOZZ.js
- custom-c2: github.com (reconstructed) in assets/markdown-rngvaYIh.js
- custom-c2: https://cloud-api.livekit.io (plaintext) in assets/livekit-C0E_jLSz.js
(+16 more)
EXFIL
- Corporate Environment Targeting in assets/livekit-C0E_jLSz.js: "tMonitor(),this.addTrackPublication(q),this.emit(I.LocalTrackPublished,q),it(e)&..."
- Corporate Environment Targeting in assets/proxy-runtime-1NyFshf9.js: "tMounts(I);Object.keys(Q.nameTable).forEach(D=>{for(var G=Q.nameTable[D];G;){var..."
- Data Encoding for Exfiltration in assets/AiPage-CFg0RGso.js: "encodeURIComponent(_0x239d04)),{'credentials':_0x2fa41e})[_0x4b6b78(0x23b,0x93,_..."
- Data Encoding for Exfiltration in assets/ChatPage-zoA8Z6RX.js: "encodeURIComponent(_0x1164f2)),'members':()=>_0x1f559(_0x157e0c(0x197,0x33f,0x52..."
- Data Encoding for Exfiltration in assets/boot-CVPGRFHh.js: "btoa("
- Data Encoding for Exfiltration in assets/index-CJm_PfL2.js: "encodeURIComponent(_0x9941f9)),{'credentials':Gt});if(!_0x3b8931['ok'])return[];..."
- Data Encoding for Exfiltration in assets/livekit-C0E_jLSz.js: "btoa("
- Dynamic C2 Endpoint Construction in assets/livekit-C0E_jLSz.js: "function Zh(){if(pa)return Ae;pa=1;var n=$h(),e=Xh(),t=hs();return Ae.grammar=t,..."
(+9 more)
OBFUSCATION
- Decoded Base64 Content in assets/fingerprint-Y5nV5FVa.js (x78)
- IOCs Found in Deobfuscated Code in assets/boot-CVPGRFHh.js
- Obfuscation: augmented proxied array function replacements in assets/AccountPage-DxKWDNtX.js
- Obfuscation: augmented proxied array function replacements in assets/AiPage-CFg0RGso.js
- Obfuscation: augmented proxied array function replacements in assets/ChatPage-zoA8Z6RX.js
- Obfuscation: augmented proxied array function replacements in assets/DarkVeil-DxeuvlMa.js
- Obfuscation: augmented proxied array function replacements in assets/GamesPage-DUKHbZws.js
- Obfuscation: augmented proxied array function replacements in assets/PlusBlockedNote-B1ILjGmj.js
(+49 more)
ADDITIONAL FINDINGS
- Reconstructed Obfuscated URL in assets/fingerprint-Y5nV5FVa.js: "https://m1.openfpcdn.io/fingerprintjs/v5.2.0/npm-monitoring"
- Publisher Has Other Malicious Packages
- Dynamic Code Execution in assets/emoji-BAJ2KL4a.js: "exec(ke)"
- Clipboard Access in assets/emoji-BAJ2KL4a.js: "electronic","low energy","low battery"],u:"1faab",a:"14"},{n:["plug","electric",..."
- XOR-Encoded String Arrays in assets/proxy-runtime-1NyFshf9.js: "var zA=[31,29,31,30,31,30,31,31,30,31,30,31]"
- Publisher Shows Burner-Account Pattern
PAYLOAD FILES
assets/fingerprint-Y5nV5FVa.js
INDICATORS (IOCs)
- urls: https://tailwindcss.com, https://app.readpeak.com/ads, http://g1.v.fwmrm.net/ad/, http://ad2.trafficgate.net/, https://ad.letmeads.com/ (+22 more)
- domains: twemoji.maxcdn.com, A.Space, fingerprint.com, tailwindcss.com, n.group (+48 more)
- payloadFileHash: 35b4bf1068cc452053f87ad7b4432d00354f576e50151e0298c1767df6519b6d
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | ishowfeet18 | all (affected) | — |
Aliases
Browse GCVE Records
75,797 records in the GCVE database · Updated August 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.