VDB
GCVE-110-OSM-2026-9292
GCVE-110-OSM-2026-9292
Advisory PublishedCVSS 5.4/10
Malicious package detected. Behaviors: data exfiltration.
ENTRY
dist/cli.js (bin: ./dist/cli.js)
EXFIL
- Network Request in dist/controller.js: "Requests.get("
ADDITIONAL FINDINGS
- Download Execute Delete Pattern in dist/cli.js: "spawn } from 'child_process'; import { writeFileSync, openSync, unlink"
- Detached Child Process Payload in dist/cli.js: "spawn(nodePath, [scriptPath, '-p', String(localPort)], { detached: true"
PAYLOAD FILES
dist/cli.js (+ dist/controller.js)
Indicators recorded in verified_iocs.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @feng3d/ctc | 0.2.1 (affected) | — |
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.