VDB
GCVE-110-OSM-2026-8697
GCVE-110-OSM-2026-8697
Advisory PublishedCVSS 9.6/10
This package is an unambiguous recon/exfiltration implant. On install, the preinstall hook executes index.js which collects the victim's public IP (via ipify.org), username, hostname, OS platform, architecture, and working directory, then POSTs the full report to a hardcoded Telegram bot (token 8236864682:AAFO8n3ml54y_JQnAA2_wxD5j01eooMwC8w, chat ID 8655055695) with the message '🚨 *HIT: core* 🚨'. The comment '// Stealth mode: execute silently' confirms adversarial intent. The publisher 'alonebeast5512' has a 100% malicious-package ratio across all 6 of their other packages (browserslist-db, devsite-youtube, update-db, etc.), and this package also depends on the known-malicious 'update-db'. This is a supply-chain implant consistent with a systematic campaign by a single threat actor seeding multiple packages with Telegram-based victim notification.
ENTRY
index.js (install-hook: node index.js)
- Install Hook Executes Local JS File in package.json
DESTINATION
- telegram-bot: 8236864682:AAFO8n3ml54y_JQnAA2_wxD5j01eooMwC8w (primary, plaintext) in index.js
EXFIL
- HTTP Data Exfiltration in index.js: "Fetch Failed* \nHost: ${os.hostname()}\nUser: ${os.userInfo()"
- Network Request in index.js: "https.request("
- System Information Collection in index.js: "os.userInfo()"
ADDITIONAL FINDINGS
- Publisher Has Other Malicious Packages
- Malicious Dependency Detected (OSM) in package.json
- Malicious Dependency Detected in package.json
PAYLOAD FILES
index.js
INDICATORS (IOCs)
- payloadFileHash: 02e94cc73997b85183d04db7827e1384d22ac53cc3f225f748d36b0c14b50011
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | amazon-core | all (affected) | — |
Aliases
Browse GCVE Records
75,797 records in the GCVE database · Updated August 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.