VDB

GCVE-110-OSM-2026-8541

GCVE-110-OSM-2026-8541
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 19, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code. ENTRY bin/vite.js (bin: bin/vite.js) DESTINATION - reconstructed: https://github.com/rollup/plugins/tree/master/packages/dynamic-import-vars#limitations (primary, reconstructed) in dist/node/chunks/dep-Cy9twKMn.js - custom-c2: https://lodash.com/ (plaintext) in dist/node/chunks/dep-BkYu-SNl.js - custom-c2: https://lodash.com/license (plaintext) in dist/node/chunks/dep-BkYu-SNl.js - custom-c2: http://underscorejs.org/LICENSE (plaintext) in dist/node/chunks/dep-BkYu-SNl.js - custom-c2: https://mathiasbynens.be/notes/javascript-unicode (plaintext) in dist/node/chunks/dep-BkYu-SNl.js - custom-c2: http://eev.ee/blog/2015/09/12/dark-corners-of-unicode/ (plaintext) in dist/node/chunks/dep-BkYu-SNl.js - custom-c2: http://ecma-international.org/ecma-262/7.0/#sec-object.prototype.tostring (plaintext) in dist/node/chunks/dep-BkYu-SNl.js - custom-c2: https://mathiasbynens.be/notes/css-escapes (plaintext) in dist/node/chunks/dep-BkYu-SNl.js (+43 more) EXFIL - Corporate Environment Targeting in dist/node/chunks/dep-Cy9twKMn.js: "tMode: true }); if (!filter || filter" - Data Encoding for Exfiltration in dist/client/client.mjs: "encodeURIComponent(file" - Data Encoding for Exfiltration in dist/node/chunks/dep-Cy9twKMn.js: "Buffer.from(str, 'utf-8').toString('base64')" - Data Encoding for Exfiltration in dist/node-cjs/publicUtils.cjs: "Buffer.from(json, 'utf8').toString('base64')" - System Information Collection in dist/node/chunks/dep-BkYu-SNl.js: "process.platform" - Network Request in dist/node/chunks/dep-Cy9twKMn.js: "Requests.get(" - System Information Collection in dist/node/chunks/dep-Cy9twKMn.js: "process.platform" - System Information Collection in dist/node/cli.js: "process.platform" (+2 more) OBFUSCATION - Whitespace-Padded Hidden Payload in bin/vite.js: "; global" - Obfuscation: function to array replacements in bin/vite.js - Dynamic Base64 Decoding in dist/node/chunks/dep-Cy9twKMn.js: "atob(E)" - Dynamic Base64 Decoding in dist/node/runtime.js: "Buffer.from(str, "base64")" - Dynamic Base64 Decoding in dist/node-cjs/publicUtils.cjs: "Atob(base64)" - Base64 Encoded Payload in dist/node/chunks/dep-BkYu-SNl.js: ""AGFzbQEAAAABCAJgAX8AYAAAAwQDAQAABQMBAAEGGgV+AUIAC34BQgALfgFCAAt+AUIAC34BQgALByI..." - Base64 Encoded Payload in dist/node/chunks/dep-Cy9twKMn.js: ""AGFzbQEAAAABKwhgAX8Bf2AEf39/fwBgAAF/YAAAYAF/AGADf39/AX9gAn9/AX9gA39/fwADMTAAAQE..." - String Array Obfuscation in dist/node/chunks/dep-Cy9twKMn.js: "[ '#0000CC', '#0000FF', '#0033CC', '#0033FF', '#0066CC', '#0066FF', '#0099CC', '..." (+11 more) ADDITIONAL FINDINGS - Base64 Decoded Eval in dist/node/chunks/dep-Cy9twKMn.js: "compile((E="AGFzbQEAAAABKwhgAX8Bf2AEf39/fwBgAAF/YAAAYAF/AGADf39/AX9gAn9/AX9gA39/..." - Reconstructed Obfuscated URL in dist/node/chunks/dep-Cy9twKMn.js: "https://github.com/rollup/plugins/tree/master/packages/dynamic-import-vars#limit..." - Dynamic Code Execution in dist/client/client.mjs: "exec(text)" - Shell Command Execution in dist/node/chunks/dep-Cy9twKMn.js: "execSync(" - Suspicious TLD Domain in dist/node/chunks/dep-Cy9twKMn.js: "https://www.cl.cam" - Shell Command Variable Setup in dist/node/chunks/dep-Cy9twKMn.js: "Windows ? pathExtExe.split(colon) : ['']; if (isWindows) { if (cmd.indexOf('.') ..." (+1 more) PAYLOAD FILES dist/node/chunks/dep-Cy9twKMn.js INDICATORS (IOCs) - ipv6: 0::, 0000:0000:0000:0000:0000:0000:0000:0001, 0000:0000:0000:0000:0000:0000:0000:0000 - urls: https://sindresorhus.com, https://paulmillr.com, https://mathiasbynens.be/, https://jquery.org/, http://underscorejs.org/ (+8 more) - domains: sindresorhus.com, paulmillr.com, juliangruber.com, substack.net, vision-media.ca (+12 more) - emails: justin@ridgewell.name, david@bonnet.cc, julian@juliangruber.com, mail@substack.net, hello@moxy.studio (+10 more) - payloadFileHash: 26450fcaac3be7d751a9cd27f0e3554288c79ccc77eb22522530f66ae3d8f91c

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@vite-tab/tabui7.15.16 (affected)

References

vendor

Browse GCVE Records

75,874 records in the GCVE database · Updated August 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›