VDB
GCVE-110-OSM-2026-8699
GCVE-110-OSM-2026-8699
Advisory PublishedCVSS 9.6/10
This is a dependency-confusion attack targeting @mts-pay/web-sdk (version 99.9.9 is artificially inflated to outrank an internal package). The preinstall hook executes index.js on install, which collects the full process.env (containing tokens, API keys, credentials), user info, hostname, platform, network interfaces, and install path, then POSTs the entire payload as JSON to the hardcoded C2 at 31.56.206.17:8443/websdk. The Russian-language comments explicitly describe the intent ('самое важное: токены, ключи, пути' — 'most important: tokens, keys, paths') and even note that errors should be suppressed to avoid detection ('чтобы не привлекать внимания'). The publisher 'k1nder' (email: anonimpentester@mail.ru) has 7 of 9 previously checked packages already flagged as malicious at high severity, confirming a serial malicious actor.
ENTRY
index.js (install-hook: node index.js)
- Install Hook Executes Local JS File in package.json
DESTINATION
- custom-c2: 31.56.206.17 (primary, plaintext) in index.js
EXFIL
- Network Request in index.js: "http.request("
- System Information Collection in index.js: "os.userInfo()"
ADDITIONAL FINDINGS
- Publisher Has Other Malicious Packages
PAYLOAD FILES
index.js
INDICATORS (IOCs)
- payloadFileHash: cb14a8ee2d229df7a20ac8cc0bc35130fc72cd19754f15987779c4e7e8607b80
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @mts-pay/web-sdk | all (affected) | — |
Aliases
Browse GCVE Records
75,827 records in the GCVE database · Updated August 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.