VDB
GCVE-110-OSM-2026-7916
GCVE-110-OSM-2026-7916
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code.
ENTRY
sw.js (main: sw.js)
LOOT
- Browser Data Theft in assets/layout-DKQHM32n.js: "chrome/")?Math.round:z;function un(t){t.min=cn(t.min),t.max=cn(t.max)}function F..."
- Browser Data Theft in assets/nttg54ebk2.js: "Brave\x20Sear','FiHkS','nt)]\x20focus','vars','over:bg-[v','sessionSto','1\x20md..."
- Browser Data Theft in assets/qzcpiwg4gv.js: "chrome/','controls','dmCFX','reshold','markerWidt','GdoXw','SHgpF','DolFD','aMcK..."
PERSISTENCE
- Startup Persistence in assets/index-8N-ebit3.js: ".profile"
DESTINATION
- reconstructed: https://github.com/syntax-tree/hast-util-to-jsx-runtime#cannot-parse-style-attribute (primary, reconstructed) in assets/ai-page-CPMi_fet.js
- reconstructed: https://react.dev/errors/null (reconstructed) in assets/ai-page-CPMi_fet.js
- custom-c2: react.dev (reconstructed) in assets/index-8N-ebit3.js
- custom-c2: github.com (reconstructed) in 8cfc2/hgshm.js
- custom-c2: https://publicsuffix.org/list/public_suffix_list.dat (plaintext) in 8cfc2/hgshm.js
- custom-c2: https://du (plaintext) in assets/a3g0q43tbe.js
- custom-c2: https://cd (plaintext) in assets/a3g0q43tbe.js
- custom-c2: https://mo (plaintext) in assets/a3g0q43tbe.js
(+46 more)
EXFIL
- Data Encoding for Exfiltration in 8cfc2/hgshm.js: "btoa("
- Dynamic C2 Endpoint Construction in 8cfc2/hgshm.js: "function r(e){return"string"==typeof e&&!!e.trim()}function n(e,n){var i,a,s,o,l..."
- Data Encoding for Exfiltration in assets/a3g0q43tbe.js: "encodeURIComponent(_0x546912)):void(0x5*-0x6e2+-0x269e*0x1+0x148*0x39);}catch{if..."
- Data Encoding for Exfiltration in assets/ai-page-CPMi_fet.js: "encodeURIComponent(l)),n=r+i+1,l=""),i&&(r+=i,i=0)}return t.join("")+e.slice(n)}..."
- Data Encoding for Exfiltration in assets/index-8N-ebit3.js: "encodeURIComponent(arguments[1]);for(var E=2;E<arguments.length;E++)y+="&args[]=..."
- Dynamic C2 Endpoint Construction in assets/index-8N-ebit3.js: "function Qm(e,t){return t=Xm(t),Xm(e)===t}function ke(e,t,a,l,u,r){switch(a){cas..."
- Data Encoding for Exfiltration in assets/new-tab-page-jjqO5LES.js: "encodeURIComponent(e)}`,{signal:s.current.signal});if(!b.ok){a([]);return}const ..."
- Dynamic C2 Endpoint Construction in assets/new-tab-page-jjqO5LES.js: "function Vr(...e){const n=!Array.isArray(e[0]),t=n?0:-1,a=e[0+t],s=e[1+t],u=e[2+..."
(+10 more)
OBFUSCATION
- Dynamic Base64 Decoding in 8cfc2/hgshm.js: "atob(t)"
- Obfuscation: function to array replacements in 8cfc2/hgshm.js
- Obfuscation: augmented proxied array function replacements in assets/3oruu3por5.js
- Obfuscation: augmented proxied array function replacements in assets/6y4sp7rdhb.js
- Obfuscation: augmented proxied array function replacements in assets/8qezz8tdz1.js
- Obfuscation: augmented proxied array function replacements in assets/a3g0q43tbe.js
- Obfuscation: augmented proxied array function replacements in assets/blhj60cfaf.js
- Obfuscation: augmented proxied array function replacements in assets/cl75b3c3pk.js
(+66 more)
ADDITIONAL FINDINGS
- Reconstructed Obfuscated URL in assets/ai-page-CPMi_fet.js: "https://github.com/syntax-tree/hast-util-to-jsx-runtime#cannot-parse-style-attri..."
- Dynamic Code Execution in 8cfc2/hgshm.js: "exec(p)"
- Clipboard Access in 8cfc2/hgshm.js: "navigator.clipboard.writeText"
- Silent Process Execution in 8cfc2/hgshm.js: "{silent: true"
- XOR-Encoded String Arrays in j3ve9/ls3ez.mjs: "var __MONTH_DAYS_LEAP = [31, 29, 31, 30, 31, 30, 31, 31, 30, 31, 30, 31]"
PAYLOAD FILES
8cfc2/hgshm.js (+ runtime/scramjet/scramjet.all.js, assets/ai-page-CPMi_fet.js)
INDICATORS (IOCs)
- ipv4: 1.86.47.234, 1.4.2.7, 1.3.3.6, 2.3.5.6
- ipv6: 50::, 60::, 72::, 90::
- urls: https://um, https://po, https://cl, https://se, https://abdct.com/
- domains: n.group, w.bing.com, abdct.com
- payloadFileHash: 8444505b604b82fa1497c3968d19c35277fa470c5d9088ca4536a6b8ec9c2baa
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | acidic | all (affected) | — |
Aliases
Browse GCVE Records
75,827 records in the GCVE database · Updated August 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.