VDB
GCVE-110-OSM-2026-9025
GCVE-110-OSM-2026-9025
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: obfuscated code.
OBFUSCATION
- Decoded Hex String Content in index.mjs
- Base64 Encoded Payload in index.mjs: "'68747470733a2f2f663030342e6261636b626c617a6562322e636f6d2f66696c652f64703868627..."
- recovered 1 urls, 1 domains from decoded/deobfuscated content
PAYLOAD FILES
index.mjs
INDICATORS (IOCs)
- urls: https://f004.backblazeb2.com/file/dp8hbvocjd2fpza/helper.dat
- domains: f004.backblazeb2.com
- payloadFileHash: 36590620ad2b495767f104514228efbcb4e2c2f45ba46ca10eaca797c562addf
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | streak-lib-math | all (affected) | — |
Aliases
Browse GCVE Records
77,606 records in the GCVE database · Updated August 8, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.