VDB
GCVE-110-OSM-2026-8289
GCVE-110-OSM-2026-8289
Advisory PublishedCVSS 8.8/10
This package pretends to "generate random ecommerce transactions data", but is really hiding a base64 loader in one of the javascript files.
ENTRY
index.js (main: index.js) - this file calls the test_address_list.js file
OBFUSCATION
- test_address_list.js file is an obfuscated base64 blob
PAYLOAD FILES
test_address_list.js - holds a base64 payload pretending to be a series of transaction numbers. That payload pulls a loader from dothebest.store which is another javascript file saved as "bag.php". That bag.php file is an obfuscated Python remote access trojan (RAT) which talks to the dothebest.store domain for C2.
INDICATORS (IOCs)
- payloadFileHash: 1c18e094f05c8964a92facf9ef5b03a05dcd42d9e0b60a547f99a50db51deca6
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | txs-sdk-lib | all (affected) | — |
Browse GCVE Records
75,874 records in the GCVE database · Updated August 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.