VDB

GCVE-110-OSM-2026-8186

GCVE-110-OSM-2026-8186
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published May 19, 2026
Suspicious package detected. [osmalyze-auto] Entrypoint: dist/index.js (main: dist/index.js) Exfil: api.telegram.org/bot${token}/getMe`); (telegram-bot, recovery: plaintext in dist/components/Telegram/Telegram.service.js) Payload: dist/components/clients/client.service.js Secondary files: dist/components/buffer-clients/buffer-client.service.js, dist/components/promote-clients/promote-client.service.js Key findings: - Environment Variable Exfiltration in dist/components/Telegram/utils/generateTGConfig.js: "process.env.PROXY_API_KEY || "santoor", clientId: process.env.clientId |..." - Corporate Environment Targeting in dist/components/bots/bots.service.js: "tModel.aggregate([ { $match" - Corporate Environment Targeting in dist/components/buffer-clients/buffer-client.service.js: "tMobiles = new Set(clients .filter" - Environment Variable Exfiltration in dist/components/clients/client.service.js: "process.env.uptimeChecker}/refreshmap`, { timeout: 5000 }), (0, fetc..." - Corporate Environment Targeting in dist/components/clients/client.service.js: "tModel.find(workingFilter" IOCs: - ipv4: 134.0.0.0, 31.97.59.2, 148.230.84.50, 13.228.225.19, 18.142.128.26 (+1 more) - urls: http://nestjs.com/, https://paypal.me/kamilmysliwiec, https://docs.nestjs.com/support, https://kamilmysliwiec.com, https://nestjs.com (+9 more) - domains: nestjs.com, paypal.me, docs.nestjs.com, kamilmysliwiec.com, cms.paidgirl.site (+9 more) - telegramApi: api.telegram.org/bot${token}/getMe`);, api.telegram.org/bot${bot.token}/sendMessage`,, api.telegram.org/bot${bot.token}/${method}`,, api.telegram.org/bot${bot.token}/sendMediaGroup`,, api.telegram.org/bot${token}/getMe`, (+2 more) - sha256Hashes: c430d44666289dae81f30fa7b2edebf186ecc91a2d4c71266ea6ae76388792e1, 45b7ab580deca34ae9729e97c13cfd999df04416a79116c3bfb483804f85ded4, 3facaf05f0c5fc569c5649dd359892c98a85557e3e0c847964caeb67076f4d75, e44bb8bbac7f10ecc786703fe0a6a4b952189f908707980ba8f3c8975a760962, 5e1c4c362065a6b95ff952c0eab010f04dcd2c3494e813b493ecfd4fcb9fc0d8 (+45 more) - payloadFileHash: 35b8f4d8be66c6d59b57852b331908930a35a949d316b3fd9771d30ca79f151e

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknowncommon-tg-serviceall (affected)

References

advisory
vendor

Browse GCVE Records

75,874 records in the GCVE database · Updated August 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›