VDB

GCVE-110-OSM-2026-9575

GCVE-110-OSM-2026-9575
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 4, 2026
The entrypoint file cjs/src/index.js contains an explicit remote code execution payload: it uses child_process.exec to fetch and pipe a remote shell script directly into sh, with a tracker callback URL passed as an environment variable. This is a classic supply-chain attack pattern — a thin, plausible-looking ANSI color utility used as a trojan wrapper to execute attacker-controlled code on install or import. The tracker endpoint strongly suggests victim telemetry. The publisher account (vitalii-agyn) has zero prior packages and no repository, consistent with a throwaway account created solely for this attack. ENTRY cjs/src/index.js (default-index: index.js) DESTINATION - 5 fetched-payload (urls, domains) (values recorded in verified_iocs) ADDITIONAL FINDINGS - Shell Command Execution in cjs/src/index.js: "require("child_process")" PAYLOAD FILES cjs/src/index.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownagn-terminalall (affected)

References

vendor

Browse GCVE Records

67,517 records in the GCVE database · Updated August 11, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›