Threats Tagged 'mal-2026-13364'
View all threats tagged with 'mal-2026-13364'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-13364'
Click on any threat for detailed analysis and mitigation recommendations
Malicious code in @ikbal_fadilah_vanexa01/vanexa-agent (npm) 0 The npm package @ikbal_fadilah_vanexa01/vanexa-agent contains malicious code that enables remote command execution on the host machine. The package runs an agent daemon that accepts commands from a remote phone app and executes them locally via child processes, including PowerShell and inline script evaluation. Instead of using the documented LAN-only WebSocket communication, it hardcodes two Cloudflare Workers endpoints controlled by a third party unrelated to the npm publisher. The agent's main runtime is shipped as V8 bytecode, reducing auditability and hiding the malicious network relay. This design effectively grants the relay operator full remote control over the installer's system. Join the discussion | GCVE Database | 08/05/2026, 18:16:17 UTC Added: 08/06/2026, 18:16:44 UTC |
Showing 1 to 1 of 1 result