Threats Tagged 'mal-2026-10488'
View all threats tagged with 'mal-2026-10488'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-10488'
Click on any threat for detailed analysis and mitigation recommendations
Malicious code in permcarmserver (npm) 0 The permcarmserver npm package version 1.0.0 contains malicious code that, upon requiring the module, loads a native aarch64 ELF shared library disguised as an HTML file. This library implements a VLESS-over-WebSocket proxy with a hardcoded client UUID, enabling the infected host to relay arbitrary attacker-directed TCP traffic covertly. The package deletes its own installation directory shortly after activation to evade detection while the malicious proxy continues running in memory, presenting a decoy HTML page to casual HTTP probes. Join the discussion | GCVE Database | 07/13/2026, 20:49:56 UTC Added: 07/14/2026, 09:21:34 UTC |
Showing 1 to 1 of 1 result