VDB

GCVE-110-OSM-2026-7927

GCVE-110-OSM-2026-7927
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 13, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code. ENTRY index.html (main: index.html) PERSISTENCE - Startup Persistence in assets/livekit-C0E_jLSz.js: ".profile" - Startup Persistence in assets/react-CKawGOZZ.js: ".profile" DESTINATION - reconstructed: https://m1.openfpcdn.io/fingerprintjs/v5.2.0/npm-monitoring (primary, reconstructed) in assets/fingerprint-Y5nV5FVa.js - reconstructed: https://github.com/syntax-tree/hast-util-to-jsx-runtime#cannot-parse-style-attribute (reconstructed) in assets/fingerprint-Y5nV5FVa.js - reconstructed: https://65536:65536 (reconstructed) in assets/fingerprint-Y5nV5FVa.js - reconstructed: https://react.dev/errors/null (reconstructed) in assets/fingerprint-Y5nV5FVa.js - custom-c2: 21baseballacademy.com (deobfuscated) in assets/boot-CVPGRFHh.js - custom-c2: react.dev (reconstructed) in assets/react-CKawGOZZ.js - custom-c2: github.com (reconstructed) in assets/markdown-rngvaYIh.js - custom-c2: https://cloud-api.livekit.io (plaintext) in assets/livekit-C0E_jLSz.js (+16 more) EXFIL - Corporate Environment Targeting in assets/livekit-C0E_jLSz.js: "tMonitor(),this.addTrackPublication(q),this.emit(I.LocalTrackPublished,q),it(e)&..." - Corporate Environment Targeting in assets/proxy-runtime-1NyFshf9.js: "tMounts(I);Object.keys(Q.nameTable).forEach(D=>{for(var G=Q.nameTable[D];G;){var..." - Data Encoding for Exfiltration in assets/AiPage-CFg0RGso.js: "encodeURIComponent(_0x239d04)),{'credentials':_0x2fa41e})[_0x4b6b78(0x23b,0x93,_..." - Data Encoding for Exfiltration in assets/ChatPage-zoA8Z6RX.js: "encodeURIComponent(_0x1164f2)),'members':()=>_0x1f559(_0x157e0c(0x197,0x33f,0x52..." - Data Encoding for Exfiltration in assets/boot-CVPGRFHh.js: "btoa(" - Data Encoding for Exfiltration in assets/index-CJm_PfL2.js: "encodeURIComponent(_0x9941f9)),{'credentials':Gt});if(!_0x3b8931['ok'])return[];..." - Data Encoding for Exfiltration in assets/livekit-C0E_jLSz.js: "btoa(" - Dynamic C2 Endpoint Construction in assets/livekit-C0E_jLSz.js: "function Zh(){if(pa)return Ae;pa=1;var n=$h(),e=Xh(),t=hs();return Ae.grammar=t,..." (+9 more) OBFUSCATION - Decoded Base64 Content in assets/fingerprint-Y5nV5FVa.js (x78) - IOCs Found in Deobfuscated Code in assets/boot-CVPGRFHh.js - Obfuscation: augmented proxied array function replacements in assets/AccountPage-DxKWDNtX.js - Obfuscation: augmented proxied array function replacements in assets/AiPage-CFg0RGso.js - Obfuscation: augmented proxied array function replacements in assets/ChatPage-zoA8Z6RX.js - Obfuscation: augmented proxied array function replacements in assets/DarkVeil-DxeuvlMa.js - Obfuscation: augmented proxied array function replacements in assets/GamesPage-DUKHbZws.js - Obfuscation: augmented proxied array function replacements in assets/PlusBlockedNote-B1ILjGmj.js (+49 more) ADDITIONAL FINDINGS - Reconstructed Obfuscated URL in assets/fingerprint-Y5nV5FVa.js: "https://m1.openfpcdn.io/fingerprintjs/v5.2.0/npm-monitoring" - Dynamic Code Execution in assets/emoji-BAJ2KL4a.js: "exec(ke)" - Clipboard Access in assets/emoji-BAJ2KL4a.js: "electronic","low energy","low battery"],u:"1faab",a:"14"},{n:["plug","electric",..." - XOR-Encoded String Arrays in assets/proxy-runtime-1NyFshf9.js: "var zA=[31,29,31,30,31,30,31,31,30,31,30,31]" PAYLOAD FILES assets/fingerprint-Y5nV5FVa.js INDICATORS (IOCs) - urls: https://tailwindcss.com, https://app.readpeak.com/ads, http://g1.v.fwmrm.net/ad/, http://ad2.trafficgate.net/, https://ad.letmeads.com/ (+22 more) - domains: twemoji.maxcdn.com, A.Space, fingerprint.com, tailwindcss.com, n.group (+48 more) - payloadFileHash: 35b4bf1068cc452053f87ad7b4432d00354f576e50151e0298c1767df6519b6d

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownabuden229all (affected)

References

advisory
vendor

Browse GCVE Records

75,797 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›