VDB

GCVE-110-OSM-2026-8697

GCVE-110-OSM-2026-8697
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 19, 2026
This package is an unambiguous recon/exfiltration implant. On install, the preinstall hook executes index.js which collects the victim's public IP (via ipify.org), username, hostname, OS platform, architecture, and working directory, then POSTs the full report to a hardcoded Telegram bot (token 8236864682:AAFO8n3ml54y_JQnAA2_wxD5j01eooMwC8w, chat ID 8655055695) with the message '🚨 *HIT: core* 🚨'. The comment '// Stealth mode: execute silently' confirms adversarial intent. The publisher 'alonebeast5512' has a 100% malicious-package ratio across all 6 of their other packages (browserslist-db, devsite-youtube, update-db, etc.), and this package also depends on the known-malicious 'update-db'. This is a supply-chain implant consistent with a systematic campaign by a single threat actor seeding multiple packages with Telegram-based victim notification. ENTRY index.js (install-hook: node index.js) - Install Hook Executes Local JS File in package.json DESTINATION - telegram-bot: 8236864682:AAFO8n3ml54y_JQnAA2_wxD5j01eooMwC8w (primary, plaintext) in index.js EXFIL - HTTP Data Exfiltration in index.js: "Fetch Failed* \nHost: ${os.hostname()}\nUser: ${os.userInfo()" - Network Request in index.js: "https.request(" - System Information Collection in index.js: "os.userInfo()" ADDITIONAL FINDINGS - Publisher Has Other Malicious Packages - Malicious Dependency Detected (OSM) in package.json - Malicious Dependency Detected in package.json PAYLOAD FILES index.js INDICATORS (IOCs) - payloadFileHash: 02e94cc73997b85183d04db7827e1384d22ac53cc3f225f748d36b0c14b50011

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownamazon-coreall (affected)

References

advisory
vendor

Browse GCVE Records

75,797 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›