VDB
GCVE-110-OSM-2026-8161
GCVE-110-OSM-2026-8161
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code.
ENTRY
oibWljdTg.js (bin: oibWljdTg.js)
PERSISTENCE
- Startup Persistence in func/mpry.js: ".PROFILE"
DESTINATION
- reconstructed: https://api.crunchbase.com/v4 (primary, reconstructed) in _init/props/.extractor/crunchbase/advanced.txt
- reconstructed: https://nubela.co/proxycurl/api/v2 (reconstructed) in _init/props/.extractor/linkedin/advanced.txt
- reconstructed: https://openapi.made-in-china.com/api/v1 (reconstructed) in _init/props/.extractor/madeinchina/advanced.txt
- reconstructed: https://api.pitchbook.com (reconstructed) in _init/props/.extractor/pitchbook/advanced.txt
- reconstructed: https://login.microsoftonline.com/ (reconstructed) in func/box/brlg.js
- reconstructed: https://mntmc.rip/license (reconstructed) in func/box/brlg.js
- reconstructed: https://www.example.com/path?q=1 (reconstructed) in func/box/brlg.js
- reconstructed: https://bestbuy.com (reconstructed) in func/box/brlg.js
(+8 more)
EXFIL
- Corporate Environment Targeting in func/jdg/pltfm.js: "tMode}=require('./spd'),{trimMap}=require('./dmcch'),MATCH"
- Data Encoding for Exfiltration in func/box/brlg.js: "encodeURIComponent(_0x2a896e||''),MICROSOFT_COOKIE_DOMAINS=['\x6c\x6f'+'\x67\x69..."
- Data Encoding for Exfiltration in func/box/wbml.js: "encodeURIComponent(_0x257d95||''),'\x68\x74'+'\x74\x70'+'\x73\x3a'+'\x2f\x2f'+'\..."
- Data Encoding for Exfiltration in func/glob.js: "encodeURIComponent(String(_0x2cee3a)['\x72\x65'+'\x70\x6c'+'\x61\x63'+'\x65'](/^..."
OBFUSCATION
- Decoded Base64 Content in _init/functions.txt (x2)
- Obfuscation: augmented proxied array function replacements in cmds/ath.js
- Obfuscation: augmented proxied array function replacements in cmds/box.js
- Obfuscation: augmented proxied array function replacements in cmds/cln.js
- Obfuscation: augmented proxied array function replacements in cmds/dbn.js
- Obfuscation: augmented proxied array function replacements in cmds/eml.js
- Obfuscation: augmented proxied array function replacements in cmds/emo.js
- Obfuscation: augmented proxied array function replacements in cmds/ext.js
(+2130 more)
ADDITIONAL FINDINGS
- Reconstructed Obfuscated URL in func/box/brlg.js: "https://login.microsoftonline.com/"
- Global Require Alias in func/cln/index.js: "module['\x65\x78'+'\x70\x6f'+'\x72\x74'+'\x73']=require"
- Shell Command Execution in cmds/ini.js: "require('child_process')"
- Publisher Shows Burner-Account Pattern
- Rapid Version Publishing
PAYLOAD FILES
func/snd/index.js (+ func/smx/index.js, func/rdt/index.js)
INDICATORS (IOCs)
- ipv4: 203.0.113.10
- urls: https://host, https://mail.custom.org, https://x.y/z, https://x.y/z?a=1, https://x.y:8443/z (+23 more)
- domains: outlook.office.com, outlook.live.com, login.microsoftonline.com, exch083.serverdata.net, custom.org (+39 more)
- emails: user@domain.com.txt, mpost@almaxcabo.com, user@custom.org, backup@corp.com, password@ipburger.com (+6 more)
- payloadFileHash: d23382b8bae29cd4602a059832ebb21e7df17062b7a4967d76ad656adc6a5ebf
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | monogrok | all (affected) | — |
Aliases
Browse GCVE Records
75,827 records in the GCVE database · Updated August 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.