VDB
GCVE-110-OSM-2026-8186
GCVE-110-OSM-2026-8186
Advisory PublishedCVSS 5.4/10
Suspicious package detected.
[osmalyze-auto] Entrypoint: dist/index.js (main: dist/index.js)
Exfil: api.telegram.org/bot${token}/getMe`); (telegram-bot, recovery: plaintext in dist/components/Telegram/Telegram.service.js)
Payload: dist/components/clients/client.service.js
Secondary files: dist/components/buffer-clients/buffer-client.service.js, dist/components/promote-clients/promote-client.service.js
Key findings:
- Environment Variable Exfiltration in dist/components/Telegram/utils/generateTGConfig.js: "process.env.PROXY_API_KEY || "santoor",
clientId: process.env.clientId |..."
- Corporate Environment Targeting in dist/components/bots/bots.service.js: "tModel.aggregate([
{ $match"
- Corporate Environment Targeting in dist/components/buffer-clients/buffer-client.service.js: "tMobiles = new Set(clients
.filter"
- Environment Variable Exfiltration in dist/components/clients/client.service.js: "process.env.uptimeChecker}/refreshmap`, { timeout: 5000 }),
(0, fetc..."
- Corporate Environment Targeting in dist/components/clients/client.service.js: "tModel.find(workingFilter"
IOCs:
- ipv4: 134.0.0.0, 31.97.59.2, 148.230.84.50, 13.228.225.19, 18.142.128.26 (+1 more)
- urls: http://nestjs.com/, https://paypal.me/kamilmysliwiec, https://docs.nestjs.com/support, https://kamilmysliwiec.com, https://nestjs.com (+9 more)
- domains: nestjs.com, paypal.me, docs.nestjs.com, kamilmysliwiec.com, cms.paidgirl.site (+9 more)
- telegramApi: api.telegram.org/bot${token}/getMe`);, api.telegram.org/bot${bot.token}/sendMessage`,, api.telegram.org/bot${bot.token}/${method}`,, api.telegram.org/bot${bot.token}/sendMediaGroup`,, api.telegram.org/bot${token}/getMe`, (+2 more)
- sha256Hashes: c430d44666289dae81f30fa7b2edebf186ecc91a2d4c71266ea6ae76388792e1, 45b7ab580deca34ae9729e97c13cfd999df04416a79116c3bfb483804f85ded4, 3facaf05f0c5fc569c5649dd359892c98a85557e3e0c847964caeb67076f4d75, e44bb8bbac7f10ecc786703fe0a6a4b952189f908707980ba8f3c8975a760962, 5e1c4c362065a6b95ff952c0eab010f04dcd2c3494e813b493ecfd4fcb9fc0d8 (+45 more)
- payloadFileHash: 35b8f4d8be66c6d59b57852b331908930a35a949d316b3fd9771d30ca79f151e
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | common-tg-service | all (affected) | — |
Aliases
Browse GCVE Records
75,874 records in the GCVE database · Updated August 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.