VDB
GCVE-110-OSM-2026-8541
GCVE-110-OSM-2026-8541
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code.
ENTRY
bin/vite.js (bin: bin/vite.js)
DESTINATION
- reconstructed: https://github.com/rollup/plugins/tree/master/packages/dynamic-import-vars#limitations (primary, reconstructed) in dist/node/chunks/dep-Cy9twKMn.js
- custom-c2: https://lodash.com/ (plaintext) in dist/node/chunks/dep-BkYu-SNl.js
- custom-c2: https://lodash.com/license (plaintext) in dist/node/chunks/dep-BkYu-SNl.js
- custom-c2: http://underscorejs.org/LICENSE (plaintext) in dist/node/chunks/dep-BkYu-SNl.js
- custom-c2: https://mathiasbynens.be/notes/javascript-unicode (plaintext) in dist/node/chunks/dep-BkYu-SNl.js
- custom-c2: http://eev.ee/blog/2015/09/12/dark-corners-of-unicode/ (plaintext) in dist/node/chunks/dep-BkYu-SNl.js
- custom-c2: http://ecma-international.org/ecma-262/7.0/#sec-object.prototype.tostring (plaintext) in dist/node/chunks/dep-BkYu-SNl.js
- custom-c2: https://mathiasbynens.be/notes/css-escapes (plaintext) in dist/node/chunks/dep-BkYu-SNl.js
(+43 more)
EXFIL
- Corporate Environment Targeting in dist/node/chunks/dep-Cy9twKMn.js: "tMode: true }); if (!filter || filter"
- Data Encoding for Exfiltration in dist/client/client.mjs: "encodeURIComponent(file"
- Data Encoding for Exfiltration in dist/node/chunks/dep-Cy9twKMn.js: "Buffer.from(str, 'utf-8').toString('base64')"
- Data Encoding for Exfiltration in dist/node-cjs/publicUtils.cjs: "Buffer.from(json, 'utf8').toString('base64')"
- System Information Collection in dist/node/chunks/dep-BkYu-SNl.js: "process.platform"
- Network Request in dist/node/chunks/dep-Cy9twKMn.js: "Requests.get("
- System Information Collection in dist/node/chunks/dep-Cy9twKMn.js: "process.platform"
- System Information Collection in dist/node/cli.js: "process.platform"
(+2 more)
OBFUSCATION
- Whitespace-Padded Hidden Payload in bin/vite.js: "; global"
- Obfuscation: function to array replacements in bin/vite.js
- Dynamic Base64 Decoding in dist/node/chunks/dep-Cy9twKMn.js: "atob(E)"
- Dynamic Base64 Decoding in dist/node/runtime.js: "Buffer.from(str, "base64")"
- Dynamic Base64 Decoding in dist/node-cjs/publicUtils.cjs: "Atob(base64)"
- Base64 Encoded Payload in dist/node/chunks/dep-BkYu-SNl.js: ""AGFzbQEAAAABCAJgAX8AYAAAAwQDAQAABQMBAAEGGgV+AUIAC34BQgALfgFCAAt+AUIAC34BQgALByI..."
- Base64 Encoded Payload in dist/node/chunks/dep-Cy9twKMn.js: ""AGFzbQEAAAABKwhgAX8Bf2AEf39/fwBgAAF/YAAAYAF/AGADf39/AX9gAn9/AX9gA39/fwADMTAAAQE..."
- String Array Obfuscation in dist/node/chunks/dep-Cy9twKMn.js: "[ '#0000CC', '#0000FF', '#0033CC', '#0033FF', '#0066CC', '#0066FF', '#0099CC', '..."
(+11 more)
ADDITIONAL FINDINGS
- Base64 Decoded Eval in dist/node/chunks/dep-Cy9twKMn.js: "compile((E="AGFzbQEAAAABKwhgAX8Bf2AEf39/fwBgAAF/YAAAYAF/AGADf39/AX9gAn9/AX9gA39/..."
- Reconstructed Obfuscated URL in dist/node/chunks/dep-Cy9twKMn.js: "https://github.com/rollup/plugins/tree/master/packages/dynamic-import-vars#limit..."
- Dynamic Code Execution in dist/client/client.mjs: "exec(text)"
- Shell Command Execution in dist/node/chunks/dep-Cy9twKMn.js: "execSync("
- Suspicious TLD Domain in dist/node/chunks/dep-Cy9twKMn.js: "https://www.cl.cam"
- Shell Command Variable Setup in dist/node/chunks/dep-Cy9twKMn.js: "Windows ? pathExtExe.split(colon) : ['']; if (isWindows) { if (cmd.indexOf('.') ..."
(+1 more)
PAYLOAD FILES
dist/node/chunks/dep-Cy9twKMn.js
INDICATORS (IOCs)
- ipv6: 0::, 0000:0000:0000:0000:0000:0000:0000:0001, 0000:0000:0000:0000:0000:0000:0000:0000
- urls: https://sindresorhus.com, https://paulmillr.com, https://mathiasbynens.be/, https://jquery.org/, http://underscorejs.org/ (+8 more)
- domains: sindresorhus.com, paulmillr.com, juliangruber.com, substack.net, vision-media.ca (+12 more)
- emails: justin@ridgewell.name, david@bonnet.cc, julian@juliangruber.com, mail@substack.net, hello@moxy.studio (+10 more)
- payloadFileHash: 26450fcaac3be7d751a9cd27f0e3554288c79ccc77eb22522530f66ae3d8f91c
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @vite-tab/tabui | 7.15.16 (affected) | — |
Browse GCVE Records
75,874 records in the GCVE database · Updated August 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.