VDB
GCVE-110-OSM-2025-298
GCVE-110-OSM-2025-298
Advisory PublishedCVSS 8.8/10
PolinRider (DPRK) upstream injection attempt via classic fork-and-PR. Open PR #1 from fork RAHULTALWAR123/moody-dashboard adds the PolinRider obfuscated payload (signature: "rmcej%otb%",2857687, tag 8-1489-2) to tailwind.config.js. The upstream aashwani106/moody-dashboard main branch is currently CLEAN — this is a Category B near-miss. Low-impact target (0 stars) but a clear example of the PolinRider upstream injection pattern.
=== UPSTREAM INJECTION ATTEMPT (ACTIVE, OPEN) ===
Attack type: Fork-and-PR upstream injection
Fork repo: RAHULTALWAR123/moody-dashboard (fork created 2025-10-13, 2 days after parent)
Parent repo: aashwani106/moody-dashboard (0 stars, not a fork)
PR: https://github.com/aashwani106/moody-dashboard/pull/1
PR opened: 2025-10-13
PR title: ui design and cleint-side login
=== PAYLOAD ===
Infected file (in fork): tailwind.config.js
Signature: global['!']='8-1489-2'; var _$_1e42=(function(l,e){...})("rmcej%otb%",2857687)
Attack disguise: PR bundles significant legitimate-looking UI work (Login page, user store, dashboard updates) with a tiny 4-line change to tailwind.config.js adding createRequire import and appending the payload after export default config with whitespace padding.
=== PR STATUS ===
PRs to parent: 1 (open)
Parent infected: No (near miss)
=== AUTHOR ===
RAHULTALWAR123 (Rahul), 2022-12-06 account, 27 public repos, 0 followers — real developer whose account appears compromised.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Malicious package:
advisory
Browse GCVE Records
75,735 records in the GCVE database · Updated August 1, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.