VDB

GCVE-110-OSM-2026-8151

GCVE-110-OSM-2026-8151
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 15, 2026
Malicious package detected. Behaviors: data exfiltration. ENTRY dist/index.js (main: ./dist/index.js) EXFIL - Corporate Environment Targeting in dist/index.js: "tModel = agent.model; if (agentModel !== void 0 && !knownAgentModelAliases.inclu..." - Data Encoding for Exfiltration in dist/index.js: "btoa(" - System Information Collection in dist/index.js: "process.platform" ADDITIONAL FINDINGS - Detached Child Process Payload in dist/index.js: "spawn(process.execPath, [tmpPath], { detached: true" - Publisher Has Other Malicious Packages - Rapid Version Publishing PAYLOAD FILES dist/index.js INDICATORS (IOCs) - urls: https://claude.ai/install.sh, https://sdk.vercel.ai/ - domains: docs.claude.com, claude.ai, sdk.vercel.ai - payloadFileHash: b97b95abbeba4d8a422e1df60d412eb028aebca6e7872bde61d85172ed78886e

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownai-pro-sdk2.0.3 (affected)

References

advisory
vendor

Browse GCVE Records

75,788 records in the GCVE database · Updated August 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›