VDB

GCVE-110-OSM-2026-8161

GCVE-110-OSM-2026-8161
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 15, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code. ENTRY oibWljdTg.js (bin: oibWljdTg.js) PERSISTENCE - Startup Persistence in func/mpry.js: ".PROFILE" DESTINATION - reconstructed: https://api.crunchbase.com/v4 (primary, reconstructed) in _init/props/.extractor/crunchbase/advanced.txt - reconstructed: https://nubela.co/proxycurl/api/v2 (reconstructed) in _init/props/.extractor/linkedin/advanced.txt - reconstructed: https://openapi.made-in-china.com/api/v1 (reconstructed) in _init/props/.extractor/madeinchina/advanced.txt - reconstructed: https://api.pitchbook.com (reconstructed) in _init/props/.extractor/pitchbook/advanced.txt - reconstructed: https://login.microsoftonline.com/ (reconstructed) in func/box/brlg.js - reconstructed: https://mntmc.rip/license (reconstructed) in func/box/brlg.js - reconstructed: https://www.example.com/path?q=1 (reconstructed) in func/box/brlg.js - reconstructed: https://bestbuy.com (reconstructed) in func/box/brlg.js (+8 more) EXFIL - Corporate Environment Targeting in func/jdg/pltfm.js: "tMode}=require('./spd'),{trimMap}=require('./dmcch'),MATCH" - Data Encoding for Exfiltration in func/box/brlg.js: "encodeURIComponent(_0x2a896e||''),MICROSOFT_COOKIE_DOMAINS=['\x6c\x6f'+'\x67\x69..." - Data Encoding for Exfiltration in func/box/wbml.js: "encodeURIComponent(_0x257d95||''),'\x68\x74'+'\x74\x70'+'\x73\x3a'+'\x2f\x2f'+'\..." - Data Encoding for Exfiltration in func/glob.js: "encodeURIComponent(String(_0x2cee3a)['\x72\x65'+'\x70\x6c'+'\x61\x63'+'\x65'](/^..." OBFUSCATION - Decoded Base64 Content in _init/functions.txt (x2) - Obfuscation: augmented proxied array function replacements in cmds/ath.js - Obfuscation: augmented proxied array function replacements in cmds/box.js - Obfuscation: augmented proxied array function replacements in cmds/cln.js - Obfuscation: augmented proxied array function replacements in cmds/dbn.js - Obfuscation: augmented proxied array function replacements in cmds/eml.js - Obfuscation: augmented proxied array function replacements in cmds/emo.js - Obfuscation: augmented proxied array function replacements in cmds/ext.js (+2130 more) ADDITIONAL FINDINGS - Reconstructed Obfuscated URL in func/box/brlg.js: "https://login.microsoftonline.com/" - Global Require Alias in func/cln/index.js: "module['\x65\x78'+'\x70\x6f'+'\x72\x74'+'\x73']=require" - Shell Command Execution in cmds/ini.js: "require('child_process')" - Publisher Shows Burner-Account Pattern - Rapid Version Publishing PAYLOAD FILES func/snd/index.js (+ func/smx/index.js, func/rdt/index.js) INDICATORS (IOCs) - ipv4: 203.0.113.10 - urls: https://host, https://mail.custom.org, https://x.y/z, https://x.y/z?a=1, https://x.y:8443/z (+23 more) - domains: outlook.office.com, outlook.live.com, login.microsoftonline.com, exch083.serverdata.net, custom.org (+39 more) - emails: user@domain.com.txt, mpost@almaxcabo.com, user@custom.org, backup@corp.com, password@ipburger.com (+6 more) - payloadFileHash: d23382b8bae29cd4602a059832ebb21e7df17062b7a4967d76ad656adc6a5ebf

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownmonogrokall (affected)

References

advisory
vendor

Browse GCVE Records

75,827 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›