VDB
GCVE-110-OSM-2026-9593
GCVE-110-OSM-2026-9593
Advisory PublishedCVSS 8.8/10
The package wraps libsignal-node, a cryptographic protocol library, which makes obfuscated code in src/session_record.js particularly concerning since the legitimate upstream source is fully readable. Deobfuscation recovered 17 hidden strings from session_record.js.
ENTRY
index.js (main: index.js)
OBFUSCATION
- Dynamic Base64 Decoding in src/session_record.js: "Buffer.from(k, 'base64')"
- Strings Extracted from Deobfuscated Code in src/session_record.js
ADDITIONAL FINDINGS
- Publisher Has Other Malicious Packages
PAYLOAD FILES
src/session_record.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @alannxd/libsignal-node | all (affected) | — |
Browse GCVE Records
68,087 records in the GCVE database · Updated August 18, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.