VDB

GCVE-110-OSM-2026-9292

GCVE-110-OSM-2026-9292
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published July 26, 2026
Malicious package detected. Behaviors: data exfiltration. ENTRY dist/cli.js (bin: ./dist/cli.js) EXFIL - Network Request in dist/controller.js: "Requests.get(" ADDITIONAL FINDINGS - Download Execute Delete Pattern in dist/cli.js: "spawn } from 'child_process'; import { writeFileSync, openSync, unlink" - Detached Child Process Payload in dist/cli.js: "spawn(nodePath, [scriptPath, '-p', String(localPort)], { detached: true" PAYLOAD FILES dist/cli.js (+ dist/controller.js) Indicators recorded in verified_iocs.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknown@feng3d/ctc0.2.1 (affected)

References

vendor

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›