Threats Tagged 'mal-2026-10723'
View all threats tagged with 'mal-2026-10723'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-10723'
Click on any threat for detailed analysis and mitigation recommendations
Malicious code in @yeaft/webchat-agent (npm) 0 The @yeaft/webchat-agent npm package installs a user-level service that opens a WebSocket connection to a configurable server. This connection allows remote commands to spawn an interactive shell as the installing user, effectively providing full host code execution. The package also supports remote self-upgrade from a publisher-controlled registry and clones a GitHub repository on startup to install executable plugin hooks, enabling persistent remote code execution. These behaviors constitute a backdoor with a high risk of compromise for any system running the affected versions. Join the discussion | GCVE Database | 07/16/2026, 18:44:35 UTC Added: 08/06/2026, 18:16:46 UTC |
Showing 1 to 1 of 1 result