VDB

GCVE-110-OSM-2026-7909

GCVE-110-OSM-2026-7909
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 13, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code. ENTRY sw.js (main: sw.js) LOOT - Browser Data Theft in assets/layout-DKQHM32n.js: "chrome/")?Math.round:z;function un(t){t.min=cn(t.min),t.max=cn(t.max)}function F..." - Browser Data Theft in assets/nttg54ebk2.js: "Brave\x20Sear','FiHkS','nt)]\x20focus','vars','over:bg-[v','sessionSto','1\x20md..." - Browser Data Theft in assets/qzcpiwg4gv.js: "chrome/','controls','dmCFX','reshold','markerWidt','GdoXw','SHgpF','DolFD','aMcK..." PERSISTENCE - Startup Persistence in assets/index-8N-ebit3.js: ".profile" DESTINATION - reconstructed: https://github.com/syntax-tree/hast-util-to-jsx-runtime#cannot-parse-style-attribute (primary, reconstructed) in assets/ai-page-CPMi_fet.js - reconstructed: https://react.dev/errors/null (reconstructed) in assets/ai-page-CPMi_fet.js - custom-c2: react.dev (reconstructed) in assets/index-8N-ebit3.js - custom-c2: github.com (reconstructed) in 8cfc2/hgshm.js - custom-c2: https://publicsuffix.org/list/public_suffix_list.dat (plaintext) in 8cfc2/hgshm.js - custom-c2: https://du (plaintext) in assets/a3g0q43tbe.js - custom-c2: https://cd (plaintext) in assets/a3g0q43tbe.js - custom-c2: https://mo (plaintext) in assets/a3g0q43tbe.js (+46 more) EXFIL - Data Encoding for Exfiltration in 8cfc2/hgshm.js: "btoa(" - Dynamic C2 Endpoint Construction in 8cfc2/hgshm.js: "function r(e){return"string"==typeof e&&!!e.trim()}function n(e,n){var i,a,s,o,l..." - Data Encoding for Exfiltration in assets/a3g0q43tbe.js: "encodeURIComponent(_0x546912)):void(0x5*-0x6e2+-0x269e*0x1+0x148*0x39);}catch{if..." - Data Encoding for Exfiltration in assets/ai-page-CPMi_fet.js: "encodeURIComponent(l)),n=r+i+1,l=""),i&&(r+=i,i=0)}return t.join("")+e.slice(n)}..." - Data Encoding for Exfiltration in assets/index-8N-ebit3.js: "encodeURIComponent(arguments[1]);for(var E=2;E<arguments.length;E++)y+="&args[]=..." - Dynamic C2 Endpoint Construction in assets/index-8N-ebit3.js: "function Qm(e,t){return t=Xm(t),Xm(e)===t}function ke(e,t,a,l,u,r){switch(a){cas..." - Data Encoding for Exfiltration in assets/new-tab-page-jjqO5LES.js: "encodeURIComponent(e)}`,{signal:s.current.signal});if(!b.ok){a([]);return}const ..." - Dynamic C2 Endpoint Construction in assets/new-tab-page-jjqO5LES.js: "function Vr(...e){const n=!Array.isArray(e[0]),t=n?0:-1,a=e[0+t],s=e[1+t],u=e[2+..." (+10 more) OBFUSCATION - Dynamic Base64 Decoding in 8cfc2/hgshm.js: "atob(t)" - Obfuscation: function to array replacements in 8cfc2/hgshm.js - Obfuscation: augmented proxied array function replacements in assets/3oruu3por5.js - Obfuscation: augmented proxied array function replacements in assets/6y4sp7rdhb.js - Obfuscation: augmented proxied array function replacements in assets/8qezz8tdz1.js - Obfuscation: augmented proxied array function replacements in assets/a3g0q43tbe.js - Obfuscation: augmented proxied array function replacements in assets/blhj60cfaf.js - Obfuscation: augmented proxied array function replacements in assets/cl75b3c3pk.js (+66 more) ADDITIONAL FINDINGS - Reconstructed Obfuscated URL in assets/ai-page-CPMi_fet.js: "https://github.com/syntax-tree/hast-util-to-jsx-runtime#cannot-parse-style-attri..." - Dynamic Code Execution in 8cfc2/hgshm.js: "exec(p)" - Clipboard Access in 8cfc2/hgshm.js: "navigator.clipboard.writeText" - Silent Process Execution in 8cfc2/hgshm.js: "{silent: true" - XOR-Encoded String Arrays in j3ve9/ls3ez.mjs: "var __MONTH_DAYS_LEAP = [31, 29, 31, 30, 31, 30, 31, 31, 30, 31, 30, 31]" PAYLOAD FILES 8cfc2/hgshm.js (+ runtime/scramjet/scramjet.all.js, assets/ai-page-CPMi_fet.js) INDICATORS (IOCs) - ipv4: 1.86.47.234, 1.4.2.7, 1.3.3.6, 2.3.5.6 - ipv6: 50::, 60::, 72::, 90:: - urls: https://um, https://po, https://cl, https://se - domains: n.group, w.bing.com - payloadFileHash: 8444505b604b82fa1497c3968d19c35277fa470c5d9088ca4536a6b8ec9c2baa

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowntestdonotredeemitall (affected)

References

advisory
vendor

Browse GCVE Records

75,797 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›