VDB

GCVE-110-OSM-2026-9115

GCVE-110-OSM-2026-9115
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published July 24, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code. ENTRY dist/index.js (main: dist/index.js) DESTINATION - custom-c2: http://wiki.commonjs.org/wiki/Unit_Testing/1.0\n//\n// (primary, plaintext) in dist/es/polyfills.js - custom-c2: http://narwhaljs.org (plaintext) in dist/es/polyfills.js - custom-c2: http://feross.org (plaintext) in dist/es/polyfills.js - custom-c2: http://bevry.me\ (plaintext) in dist/es/polyfills.js - custom-c2: http://blog.izs.me/ (plaintext) in dist/es/polyfills.js - custom-c2: http://dominictarr.com (plaintext) in dist/es/polyfills.js - custom-c2: http://jensarps.de/ (plaintext) in dist/es/polyfills.js - custom-c2: http://feross.org\nAuthor: (plaintext) in dist/es/polyfills.js (+57 more) EXFIL - Data Encoding for Exfiltration in dist/es/polyfills.js: "encodeURIComponent(stringifyPrimitive(k)) + eq;\n if (isArray(obj[k])) {\n retur..." - Dynamic C2 Endpoint Construction in dist/es/polyfills.js: "function blobConstructor() {\n if (typeof _blobConstructor !== 'undefined') {\n ..." - Data Encoding for Exfiltration in dist/polyfills.js: "encodeURIComponent(stringifyPrimitive(k)) + eq;\n if (isArray(obj[k])) {\n retur..." - Dynamic C2 Endpoint Construction in dist/polyfills.js: "function blobConstructor() {\n if (typeof _blobConstructor !== 'undefined') {\n ..." - System Information Collection in dist/index.js: "process.platform" OBFUSCATION - Decoded Base64 Content in dist/index.js - Obfuscation patterns: charCodeArrayBuild, charCodeChain in dist/es/polyfills.js - Obfuscation patterns: charCodeArrayBuild, charCodeChain in dist/polyfills.js ADDITIONAL FINDINGS - Dynamic Code Execution in dist/es/polyfills.js: "eval(code)" - XOR-Encoded String Arrays in dist/es/polyfills.js: "var bl_order = [16, 17, 18, 0, 8, 7, 9, 6, 10, 5, 11, 4, 12, 3, 13, 2, 14, 1, 15..." - Shell Command Execution in dist/index.js: "require('child_process')" - Silent Process Execution in dist/index.js: "stdio: 'ignore'" - Brand New Package PAYLOAD FILES dist/es/polyfills.js (+ dist/polyfills.js, dist/index.js) INDICATORS (IOCs) - emails: feross@feross.org, r@va.gg, john@chesl.es, max@maxogden.com, julian@juliangruber.com (+14 more) - payloadFileHash: 95eed5d490a4b29f0bac7e8fb9980a7f37f3901762a2afe152b89c4e21cf00f9

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownrollup-packages-node-polyfills0.13.2 (affected)

Browse GCVE Records

75,788 records in the GCVE database · Updated August 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›