VDB

GCVE-110-OSM-2026-8289

GCVE-110-OSM-2026-8289
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published July 18, 2026
This package pretends to "generate random ecommerce transactions data", but is really hiding a base64 loader in one of the javascript files. ENTRY index.js (main: index.js) - this file calls the test_address_list.js file OBFUSCATION - test_address_list.js file is an obfuscated base64 blob PAYLOAD FILES test_address_list.js - holds a base64 payload pretending to be a series of transaction numbers. That payload pulls a loader from dothebest.store which is another javascript file saved as "bag.php". That bag.php file is an obfuscated Python remote access trojan (RAT) which talks to the dothebest.store domain for C2. INDICATORS (IOCs) - payloadFileHash: 1c18e094f05c8964a92facf9ef5b03a05dcd42d9e0b60a547f99a50db51deca6

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowntxs-sdk-liball (affected)

References

vendor

Browse GCVE Records

75,874 records in the GCVE database · Updated August 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›