VDB

GCVE-110-OSM-2026-8162

GCVE-110-OSM-2026-8162
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 15, 2026
Malicious package detected. Behaviors: data exfiltration. ENTRY index.js (main: index.js) DESTINATION - reconstructed: https://myaccount.google.com/signinoptions/rescuephone?hl=en&rapt=null (primary, reconstructed) in index.js - custom-c2: myaccount.google.com (reconstructed) in index.js - custom-c2: https://sever1.tempxapi.com/api/sms (plaintext) in index.js - custom-c2: sever1.tempxapi.com (plaintext) in index.js - custom-c2: 99.0.0.0 (plaintext) in index.js - custom-c2: 132.0.0.0 (plaintext) in index.js - custom-c2: 8.0.0.0 (plaintext) in index.js - custom-c2: 24.0.0.0 (plaintext) in index.js (+1 more) EXFIL - Data Encoding for Exfiltration in index.js: "encodeURIComponent(at" - Network Request in index.js: "fetch('https:" OBFUSCATION - recovered 1 urls, 1 domains from decoded/deobfuscated content ADDITIONAL FINDINGS - Reconstructed Obfuscated URL in index.js: "https://myaccount.google.com/signinoptions/rescuephone?hl=en&rapt=null" PAYLOAD FILES index.js INDICATORS (IOCs) - payloadFileHash: 0c22e3b082138f27016660c387a7c96c2fdbcdf9fc4a89ae8b4b546d7eec800e

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowngmail-changer2.0.4 (affected)

References

advisory
vendor

Browse GCVE Records

75,875 records in the GCVE database · Updated August 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›