Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-506'

View all threats tagged with 'cwe-506'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-506

Threats Tagged 'cwe-506'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-48159: CWE-506: Embedded Malicious Code in dai-shi use-reducer-asyncCVE-2026-48159
0

The use-reducer-async React package contained malicious commits in its default branch between 2026-05-18 and 2026-05-19 that executed attacker-controlled code during npm install on developer machines. The malicious code fetched and executed a remote payload, disabling TLS verification and targeting developer workstations while skipping CI and cloud environments. The commits were removed by force-push, but local clones and forks may still contain the malicious code. The package was not published to npm. Machines that ran npm install on an affected checkout during this period should be considered compromised and require credential rotation and auditing.

Join the discussion
CVE-2026-48158: CWE-506: Embedded Malicious Code in dai-shi use-context-selectorCVE-2026-48158
0

The use-context-selector React hook package contained malicious commits for about one day in May 2026 that executed attacker-controlled code during npm install on developer machines. The malicious code fetched and ran a second-stage payload from an attacker-controlled server, disabling TLS verification. The package was not published to npm, but local clones or forks with the affected commits remain vulnerable. Machines that ran npm install on an affected checkout during this period should be considered compromised and require credential rotation and auditing.

Join the discussion
CVE-2026-66747: CWE-506 Embedded Malicious Code in Zbtlink CPE2801 FirmwareCVE-2026-66747
0

Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root.

Join the discussion
CVE-2026-18072: CWE-506 Embedded Malicious Code in nico23 Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick …CVE-2026-18072
0

The Advanced Responsive Video Embedder plugin for WordPress version 10.8.7 contains a critical authentication bypass vulnerability due to a hardcoded backdoor token. This backdoor allows unauthenticated attackers to gain administrator privileges by supplying a known token that matches a hardcoded SHA-256 hash in the plugin source. The vulnerability arises because the authentication bypass occurs before any normal authentication checks, with no nonce or capability verification. This flaw was likely introduced maliciously by an attacker with commit access to the plugin's codebase.

Join the discussion
CVE-2026-46412: CWE-506: Embedded Malicious Code in BeProduct beproduct-org-nestjs-authCVE-2026-46412
0

@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions of `@beproduct/nestjs-auth` (0.1.2 through 0.1.19). The postinstall payload attempted to harvest npm tokens (from `~/.npmrc`); GitHub personal access tokens, OAuth tokens (`gho_*`), and Actions OIDC tokens; AWS credentials (from environment variables and `~/.aws/credentials`); HashiCorp Vault tokens; and other secrets present in environment variables. Version `0.1.20` is a clean republish from the original `0.1.1` source tree. Anyone who installed any version in the range `>=0.1.2 <=0.1.19` should remove the package and clean the npm cache; install the clean version; rotate every credential present in the install environment, including all npm publish tokens, all GitHub PATs and OAuth tokens, AWS access keys, HashiCorp Vault tokens, and any other secret that was in env vars or config files at install time; scan affected hosts for indicators of compromise and, if any are found, treat the host as compromised and reimage; and check committed repository history for unexpected additions in `.claude/` or `.vscode/` directories. The worm is known to commit `setup.mjs` + hook configs to PR branches via automated agent runtimes.

Join the discussion
CVE-2026-46421: CWE-506: Embedded Malicious Code in cap-js @cap-js/sqliteCVE-2026-46421
0

The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2026, compromised versions of `@cap-js/[email protected]`, `@cap-js/[email protected]`, and `@cap-js/[email protected]` were published. The malicious packages harvested credentials and attempted self-propagation. If a compromised version was installed, all credentials accessible on that machine (npm tokens, cloud provider credentials, SSH keys, GitHub PATs) should be considered compromised. User should upgrade to `@cap-js/sqlite` >= 2.4.0, `@cap-js/postgres` >= 2.3.0, `@cap-js/db-service` >= 2.11.0. If a compromised version was ever installed, rotate all affected credentials. No known workarounds are available.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Tag: cwe-506
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses