VDB

GCVE-110-OSM-2026-8917

GCVE-110-OSM-2026-8917
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 22, 2026
This package contains a clearly malicious persistence implant disguised as a calendar/streak utility. The IIFE in index.mjs detects a WSL Linux environment (checks for /mnt/c and NTUSER.DAT), enumerates Windows user profiles, then fetches a binary from a Backblaze B2 bucket (https://f004.backblazeb2.com/file/YOUR_BUCKET_NAME/vite-deps.dat) and writes it to the Windows Startup folder as 'vite-native-helper.exe' — a classic persistence-via-startup mechanism. The URL is deliberately reconstructed from fragments (p, h, b, f) to evade static URL detection. The attacker model is supply-chain compromise targeting WSL developers: the package installs a Windows executable that runs on every login. DESTINATION - reconstructed: https://f004.backblazeb2.com/file/YOUR_BUCKET_NAME/vite-deps.dat (primary, reconstructed) in index.mjs - custom-c2: f004.backblazeb2.com (reconstructed) in index.mjs EXFIL - System Information Collection in index.mjs: "process.platform" OBFUSCATION - recovered 1 urls, 1 domains from decoded/deobfuscated content ADDITIONAL FINDINGS - Reconstructed Obfuscated URL in index.mjs: "https://f004.backblazeb2.com/file/YOUR_BUCKET_NAME/vite-deps.dat" PAYLOAD FILES index.mjs INDICATORS (IOCs) - payloadFileHash: 73935265e043e14c5a17daa662019204cbd98da378a3672f83f754f3d229a5fd

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownstreak-daycountall (affected)

References

vendor

Browse GCVE Records

75,792 records in the GCVE database · Updated August 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›