Threadlinqs IntelligenceStart free

Weakness · ClassCWE-506

CWE-506: Embedded Malicious Code

KEV-linkedClass

As of 2026-10-05, CWE-506 (Embedded Malicious Code) underlies 9 CVEs tracked by Threadlinqs, 5 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 356 tracked threats.

CVEs
9Mapped to CWE-506
CISA KEV
5Exploited in the wild
Critical
4CVSS v3 critical CVEs
Threats
356Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-506?

The product contains code that appears to be malicious in nature.

Malicious flaws have acquired colorful names, including Trojan horse, trapdoor, timebomb, and logic-bomb. A developer might insert malicious code with the intent to subvert the security of a product or its host system at some time in the future. It generally refers to a program that performs a useful service but exploits rights of the program's user in a way the user does not intend.

CWE-506 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific.

Source: MITRE CWE (CWE-506 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Confidentiality, Integrity, Availability — Execute Unauthorized Code or Commands

Source: MITRE CWE, common consequences.

How CWE-506 is exploited in the wild

Threadlinqs maps 9 CVEs to CWE-506, published between 2024-03-29 and 2026-09-24. 5 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 2 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 4 critical, 4 high. The highest EPSS score in the set is 91.3% (CVE-2025-30066), the modelled probability of exploitation in the next 30 days. 356 tracked threats reference CWE-506 directly or through a CVE it covers; the most recent is “MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer” (2026-09-30). Affected products concentrate in @tanstack (1), Aquasec (1), Litellm (1), among 10 vendors in total.

Vulnerabilities (CVEs)

All 9 CVEs mapped to CWE-506, CISA KEV first, then by CVSS score.

  • CVE-2026-48027 — CISA KEV · CVSS 9.8 critical · EPSS 26.8% · published 2026-05-27
  • CVE-2026-45321 — CISA KEV · CVSS 9.6 critical · EPSS 15.0% · published 2026-05-12
  • CVE-2026-33634 — CISA KEV · CVSS 8.8 high · EPSS 21.1% · published 2026-03-23
  • CVE-2025-30066 — CISA KEV · CVSS 8.6 high · EPSS 91.3% · published 2025-03-15
  • CVE-2025-30154 — CISA KEV · CVSS 8.6 high · EPSS 15.3% · published 2025-03-19
  • CVE-2024-3094 — CVSS 10 critical · EPSS 84.9% · published 2024-03-29
  • CVE-2026-97230 — CVSS 9.8 critical · EPSS 0.2% · published 2026-09-24
  • CVE-2026-67595 — CVSS 8.1 high · EPSS 0.4% · published 2026-07-29
  • CVE-2026-48161 — EPSS 0.4% · published 2026-08-10

Affected vendors

  • @tanstack — 1 CVE
  • Aquasec — 1 CVE
  • Litellm — 1 CVE
  • Nx — 1 CVE
  • Reviewdog — 1 CVE
  • Telnyx — 1 CVE
  • Tj-actions — 1 CVE
  • Tukaani — 1 CVE
  • dai-shi — 1 CVE
  • webreinvent — 1 CVE

Threat activity

356 tracked threats cite CWE-506; the 25 most recent are listed.

Mitigations

  • Testing: Remove the malicious code and start an effort to ensure that no more malicious code exists. This may require a detailed review of all code, as it is possible to hide a serious attack in only one or two lines of code. These lines may be located almost anywhere in an application and may have been intentionally obfuscated by the attacker.

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Manual Static Analysis - Binary or Bytecode (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Binary / Bytecode disassembler - then use manual analysis for vulnerabilities & anomalies Generated Code Inspection
  • Dynamic Analysis with Manual Results Interpretation (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Automated Monitored Execution
  • Manual Static Analysis - Source Code (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Manual Source Code Review (not inspections)
  • Automated Static Analysis (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Origin Analysis

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.