# CWE-506: Embedded Malicious Code

**KEV-linked**

> As of 2026-10-05, CWE-506 (Embedded Malicious Code) underlies 9 CVEs tracked by Threadlinqs, 5 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 356 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-506?

The product contains code that appears to be malicious in nature.

Malicious flaws have acquired colorful names, including Trojan horse, trapdoor, timebomb, and logic-bomb. A developer might insert malicious code with the intent to subvert the security of a product or its host system at some time in the future. It generally refers to a program that performs a useful service but exploits rights of the program's user in a way the user does not intend.

CWE-506 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/506.html) (CWE-506 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Confidentiality, Integrity, Availability** — Execute Unauthorized Code or Commands

_Source: MITRE CWE, common consequences._

## How CWE-506 is exploited in the wild

Threadlinqs maps 9 CVEs to CWE-506, published between 2024-03-29 and 2026-09-24. 5 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 2 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 4 critical, 4 high. The highest EPSS score in the set is 91.3% (CVE-2025-30066), the modelled probability of exploitation in the next 30 days. 356 tracked threats reference CWE-506 directly or through a CVE it covers; the most recent is “MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer” (2026-09-30). Affected products concentrate in @tanstack (1), Aquasec (1), Litellm (1), among 10 vendors in total.

## Vulnerabilities (CVEs)

All 9 CVEs mapped to CWE-506, CISA KEV first, then by CVSS score.

- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027) — CISA KEV · CVSS 9.8 critical · EPSS 26.8% · published 2026-05-27
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321) — CISA KEV · CVSS 9.6 critical · EPSS 15.0% · published 2026-05-12
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634) — CISA KEV · CVSS 8.8 high · EPSS 21.1% · published 2026-03-23
- [CVE-2025-30066](https://intel.threadlinqs.com/cve/CVE-2025-30066) — CISA KEV · CVSS 8.6 high · EPSS 91.3% · published 2025-03-15
- [CVE-2025-30154](https://intel.threadlinqs.com/cve/CVE-2025-30154) — CISA KEV · CVSS 8.6 high · EPSS 15.3% · published 2025-03-19
- [CVE-2024-3094](https://intel.threadlinqs.com/cve/CVE-2024-3094) — CVSS 10 critical · EPSS 84.9% · published 2024-03-29
- [CVE-2026-97230](https://intel.threadlinqs.com/cve/CVE-2026-97230) — CVSS 9.8 critical · EPSS 0.2% · published 2026-09-24
- [CVE-2026-67595](https://intel.threadlinqs.com/cve/CVE-2026-67595) — CVSS 8.1 high · EPSS 0.4% · published 2026-07-29
- [CVE-2026-48161](https://intel.threadlinqs.com/cve/CVE-2026-48161) — EPSS 0.4% · published 2026-08-10

## Affected vendors

- **@tanstack** — 1 CVE
- **Aquasec** — 1 CVE
- **Litellm** — 1 CVE
- **Nx** — 1 CVE
- **Reviewdog** — 1 CVE
- **Telnyx** — 1 CVE
- **Tj-actions** — 1 CVE
- **Tukaani** — 1 CVE
- **dai-shi** — 1 CVE
- **webreinvent** — 1 CVE

## Threat activity

356 tracked threats cite CWE-506; the 25 most recent are listed.

- [MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer](https://intel.threadlinqs.com/threat/TL-2026-2801) — HIGH · 2026-09-30
- [Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)](https://intel.threadlinqs.com/threat/TL-2026-2806) — HIGH · 2026-09-30
- [PhantomSub: 101 Malicious npm Baileys Forks Force Developers' WhatsApp Accounts into Attacker-Controlled Groups/Channels](https://intel.threadlinqs.com/threat/TL-2026-2785) — MEDIUM · 2026-09-29
- [Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)](https://intel.threadlinqs.com/threat/TL-2026-2657) — HIGH · 2026-09-26
- [Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packages](https://intel.threadlinqs.com/threat/TL-2026-2665) — HIGH · 2026-09-26
- [DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules to Deliver Go RAT with Slack and Arbitrum Sepolia Blockchain C2](https://intel.threadlinqs.com/threat/TL-2026-2635) — HIGH · 2026-09-23
- [Rust Team Members and Popular Crate Owners Targeted via Fake Job Video Calls (North Korea-Linked)](https://intel.threadlinqs.com/threat/TL-2026-2603) — HIGH · 2026-09-21
- [GHAPPIER Loader: npm Trusted-Publishing Abuse Compromises @dforge-core/dforge-mcp](https://intel.threadlinqs.com/threat/TL-2026-2605) — HIGH · 2026-09-21
- [indexed-btree npm Campaign: Runtime-Triggered Loader Evades Install-Script Defenses via BTree.prototype.set()](https://intel.threadlinqs.com/threat/TL-2026-2590) — HIGH · 2026-09-20
- [North Korean WaterPlum (Contagious Interview) Hackers Target IT Professionals with BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, StoatWaffle Malware](https://intel.threadlinqs.com/threat/TL-2026-2577) — HIGH · 2026-09-19
- [PhantomRaven: LLM-Generated npm Information Stealer Used for Bug Bounty Hunting](https://intel.threadlinqs.com/threat/TL-2026-2531) — HIGH · 2026-09-16
- [Admin Menu Editor Pro WordPress Plugin Backdoored via Supply-Chain Compromise, 1,500 Sites Affected](https://intel.threadlinqs.com/threat/TL-2026-2524) — CRITICAL · 2026-09-15
- [SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor](https://intel.threadlinqs.com/threat/TL-2026-2497) — CRITICAL · 2026-09-14
- [ChainDrop/Mini Shai-Hulud npm Worm Compromises keyv, cacheable, and 400+ Downstream Packages via Ethereum-Resolved C2](https://intel.threadlinqs.com/threat/TL-2026-2285) — CRITICAL · 2026-09-01
- [Shai-Hulud npm Supply-Chain Worm: Two Alleged TeamPCP Members Charged by AFP/FBI](https://intel.threadlinqs.com/threat/TL-2026-2186) — CRITICAL · 2026-08-28
- [npm Supply-Chain Compromise: @7nohe/openapi-react-query-codegen Ships "Trinitite" Credential-Harvesting Worm](https://intel.threadlinqs.com/threat/TL-2026-2193) — CRITICAL · 2026-08-28
- [24 Malicious npm Packages Abuse Registry Mirrors as Phishing Infrastructure (Fake Cloudflare/Microsoft Login Pages)](https://intel.threadlinqs.com/threat/TL-2026-2150) — MEDIUM · 2026-08-26
- [GitHub Actions Supply Chain Attack: tj-actions & reviewdog Compromise (CVE-2025-30066, CVE-2025-30154)](https://intel.threadlinqs.com/threat/TL-2026-2130) — CRITICAL · 2026-08-24
- [Sophos X-Ops: Attackers Impersonate Claude, ChatGPT, Copilot and Perplexity to Distribute Infostealers, Backdoors and Malicious Browser Extensions](https://intel.threadlinqs.com/threat/TL-2026-2120) — HIGH · 2026-08-23
- [14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2](https://intel.threadlinqs.com/threat/TL-2026-2099) — CRITICAL · 2026-08-21
- [SDLC Supply Chain Attacks: ChainDrop npm Worm and Developer Pipeline Targeting](https://intel.threadlinqs.com/threat/TL-2026-2104) — HIGH · 2026-08-21
- [Popular Rust Packages With 244M Downloads Compromised in Supply Chain Attack](https://intel.threadlinqs.com/threat/TL-2026-2083) — CRITICAL · 2026-08-20
- [Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via proc-macro1 Typosquat (DPRK/Sapphire Sleet)](https://intel.threadlinqs.com/threat/TL-2026-2085) — CRITICAL · 2026-08-20
- [SilkParasite: China-Nexus APT Deploys Seven RAT Families Against Central Asian Governments](https://intel.threadlinqs.com/threat/TL-2026-2200) — HIGH · 2026-08-19
- [Operation ASTERIX: AI-Assisted Crypto Wallet Phishing/Vishing Fraud Pipeline Abuses Claude Code and Kimi](https://intel.threadlinqs.com/threat/TL-2026-2056) — HIGH · 2026-08-18

## Mitigations

- **Testing**: Remove the malicious code and start an effort to ensure that no more malicious code exists. This may require a detailed review of all code, as it is possible to hide a serious attack in only one or two lines of code. These lines may be located almost anywhere in an application and may have been intentionally obfuscated by the attacker.

_Source: MITRE CWE, potential mitigations._

## Detection methods (MITRE CWE)

- **Manual Static Analysis - Binary or Bytecode** (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Binary / Bytecode disassembler - then use manual analysis for vulnerabilities & anomalies Generated Code Inspection
- **Dynamic Analysis with Manual Results Interpretation** (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Automated Monitored Execution
- **Manual Static Analysis - Source Code** (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Manual Source Code Review (not inspections)
- **Automated Static Analysis** (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Origin Analysis

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- CWE-912 Hidden Functionality

Canonical: https://intel.threadlinqs.com/cwe/CWE-506
Source definition: https://cwe.mitre.org/data/definitions/506.html
Detection rules and IOCs for threats exploiting CWE-506 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
