VDB

GCVE-110-OSM-2026-8588

GCVE-110-OSM-2026-8588
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published July 18, 2026
The package embeds hidden tracking and email-interception infrastructure across sites built with the isite framework. The most damning evidence is `https://social-browser.com/api/ref-links?page=` recovered from obfuscated code in `apps/client-side/site_files/js/site.js` with confirmed live network calls in ref.js, site.js, and site.min.js — this silently exfiltrates page-visit data to an external domain controlled by the author. Separately, `lib/email.js` contains a reconstructed template-literal URL `http://emails.egytag.com/api/emails/add` and `lib/integrated.js` makes additional calls to egytag.com, routing email traffic from consumer sites through the developer's own service. The deliberate obfuscation of these call sites (hiding them behind function-to-array replacements and string-array access patterns in site.js and bootstrap5.js) distinguishes this from incidental vendor bundling. While the publisher has zero prior flagged packages and the domains appear to be developer-owned, deliberately concealing supply-chain tracking in a web framework is consistent with a data-harvesting supply chain attack, not an incidental integration. ENTRY apps/charts/app.js (main: app.js) PERSISTENCE - Startup Persistence in multiple files: ".profile" DESTINATION - custom-c2: http://www.d-project.com/ (deobfuscated) in apps/client-side/site_files/js/qrcode.js EXFIL - Data Encoding for Exfiltration in apps/charts/site_files/js/chart-core.js: "btoa(" - Dynamic C2 Endpoint Construction in apps/charts/site_files/js/chart-core.js: "function r(e){if(i[e])return i[e].exports;var n=i[e]={i:e,l:!1,exports:{}};retur..." - Dynamic C2 Endpoint Construction in apps/client-side/site_files/js/WebShareEditor.js: "function i(n){if(t[n])return t[n].exports;var l=t[n]={i:n,l:!1,exports:{}};retur..." OBFUSCATION - IOCs Found in Deobfuscated Code in apps/client-side/site_files/js/bootstrap5.js - IOCs Found in Deobfuscated Code in apps/client-side/site_files/js/moment.js - IOCs Found in Deobfuscated Code in apps/client-side/site_files/js/qrcode.js - IOCs Found in Deobfuscated Code in apps/client-side/site_files/js/site.js - IOCs Found in Deobfuscated Code in object-options/lib/fn.js - Dynamic Base64 Decoding in apps/charts/site_files/js/chart-core.js: "atob(t)" ADDITIONAL FINDINGS - Reconstructed Obfuscated URL in apps/client-side/site_files/js/WebShareEditor.js: "https://indent" - Malicious Dependency Detected (OSM) in apps/client-side/package.json - Dynamic Code Execution in apps/charts/site_files/js/chart-core.js: "new function(t)" - Platform Detection with Data Collection in apps/client-side/site_files/js/prism.js: "JSON.stringify({language:u.language,code:u.code,immediateClos" - XOR-Encoded String Arrays in apps/client-side/site_files/js/xlsx.js: "var ye=[16,17,18,0,8,7,9,6,10,5,11,4,12,3,13,2,14,1,15]" - Chai-Max Campaign Indicators in object-options/index.js: "'/uploads'" (+1 more) PAYLOAD FILES apps/client-side/site_files/js/angular.js (+ apps/client-side/site_files/js/moment.js, apps/charts/site_files/js/chart-core.js) INDICATORS (IOCs) - urls: https://absunstar.github.io/isite - domains: absunstar.github.io - emails: no-reply@egytag.com, ssl@isite.com, absunstar@gmail.com - sha256Hashes: 4334135645788275237931514658376742387653423921514718526246719191 - payloadFileHash: 237656fae6e39d02cd71cbcfbf91b7964eba5796aafca1bfcfff3b054ce3fed6

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownisiteall (affected)

References

advisory
vendor

Browse GCVE Records

75,797 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›