VDB

GCVE-110-OSM-2026-9045

GCVE-110-OSM-2026-9045
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 25, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, network activity, obfuscated code. ENTRY index.js (main: index.js) DESTINATION - custom-c2: https://api.jsonstorage.net/v1/json/2ef8c758-a96f-459e-b036-b3b90379a165/f89e8264-86c2-4684-94da-c3f82d59370f (primary, decoded) in lib/caller.js - custom-c2: api.jsonstorage.net (decoded) in lib/caller.js EXFIL - Environment Variable Exfiltration in lib/caller.js: "process.env.DEV_SECRET_KEY); const v = atob(process.env.DEV_SECRET_VALUE); let r..." - Fetch and Eval/Exec in lib/caller.js: "axios.get(src, { headers: { [k]: v } })).data.cookie; const handler = new Functi..." - Network Request in lib/caller.js: "axios.get(" OBFUSCATION - Global Variable Shadowing in lib/caller.js: "const process = {" - Base64 Decoded Environment Variable in lib/caller.js: "atob(process.env." - Decoded Base64 Content in lib/caller.js - Decoded Base64 Content in lib/const.js - Decoded Base64 Content in [deobfuscated] lib/caller.js - IOCs Found in Deobfuscated Code in lib/caller.js - Dynamic Base64 Decoding in lib/caller.js: "atob(process." - Base64 Encoded Payload in lib/caller.js: ""aHR0cHM6Ly9hcGkuanNvbnN0b3JhZ2UubmV0L3YxL2pzb24vMmVmOGM3NTgtYTk2Zi00NTllLWIwMzY..." (+2 more) ADDITIONAL FINDINGS - Stealth Background Process Spawning in index.js: "spawn("node", [script, JSON.stringify(args)], { detached: true, stdio: "ignore" ..." - Shell Command Execution in index.js: "require("child_process")" - Silent Process Execution in index.js: "stdio: "ignore"" - Detached Child Process Payload in index.js: "spawn("node", [script, JSON.stringify(args)], { detached: true" - Dynamic Code Execution in lib/caller.js: "Function.constructor(" PAYLOAD FILES lib/caller.js INDICATORS (IOCs) - urls: http://192.168.1.42:9200 - domains: velo.org - emails: tyler@velo.org - payloadFileHash: ffa61701ff61ebc0c6d64cf09f5bc37a74a91b03b716129b90271d758dc164b7

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownchai-as-renderedall (affected)

References

vendor

Browse GCVE Records

75,788 records in the GCVE database · Updated August 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›