VDB

GCVE-110-OSM-2026-9234

GCVE-110-OSM-2026-9234
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published July 28, 2026
The sole file index.js is aggressively obfuscated using the obfuscator.io proxied-array-function pattern, complete with an RC4 stream cipher (function `k`) layered over a base64 decoder (function `g`) and a large encrypted string table shuffled at runtime — a technique used almost exclusively by malicious npm packages to hide network endpoints and credential-theft logic from static analysis. The package ships zero meaningful metadata (no description, no repository, no author), which is a classic throwaway-account publishing shape. Deobfuscation failed, so no IOCs were recovered, but the absence of confirmed exfil strings does not exonerate the package — it means the payload is runtime-computed, which is itself a stronger evasion signal. The static scorer rated this clean at low confidence, which is consistent with the IOC-count being zero; however, the sophistication of the obfuscation in a metadata-empty utility claiming to be an 'array' helper is inconsistent with any legitimate library use-case. ENTRY index.js (main: index.js) OBFUSCATION - Obfuscation: augmented proxied array function replacements in index.js - Deobfuscation Failed in index.js PAYLOAD FILES index.js INDICATORS (IOCs) - payloadFileHash: 3a96c07468a2adea3fab5cdfdee801fdb557382a128b0e62b34f013400e5266d

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownnode-array-plusall (affected)

References

advisory
vendor

Browse GCVE Records

75,974 records in the GCVE database · Updated August 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›