VDB

GCVE-110-OSM-2025-298

GCVE-110-OSM-2025-298
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published October 13, 2025
PolinRider (DPRK) upstream injection attempt via classic fork-and-PR. Open PR #1 from fork RAHULTALWAR123/moody-dashboard adds the PolinRider obfuscated payload (signature: "rmcej%otb%",2857687, tag 8-1489-2) to tailwind.config.js. The upstream aashwani106/moody-dashboard main branch is currently CLEAN — this is a Category B near-miss. Low-impact target (0 stars) but a clear example of the PolinRider upstream injection pattern. === UPSTREAM INJECTION ATTEMPT (ACTIVE, OPEN) === Attack type: Fork-and-PR upstream injection Fork repo: RAHULTALWAR123/moody-dashboard (fork created 2025-10-13, 2 days after parent) Parent repo: aashwani106/moody-dashboard (0 stars, not a fork) PR: https://github.com/aashwani106/moody-dashboard/pull/1 PR opened: 2025-10-13 PR title: ui design and cleint-side login === PAYLOAD === Infected file (in fork): tailwind.config.js Signature: global['!']='8-1489-2'; var _$_1e42=(function(l,e){...})("rmcej%otb%",2857687) Attack disguise: PR bundles significant legitimate-looking UI work (Login page, user store, dashboard updates) with a tiny 4-line change to tailwind.config.js adding createRequire import and appending the payload after export default config with whitespace padding. === PR STATUS === PRs to parent: 1 (open) Parent infected: No (near miss) === AUTHOR === RAHULTALWAR123 (Rahul), 2022-12-06 account, 27 public repos, 0 followers — real developer whose account appears compromised.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)

References

Browse GCVE Records

75,735 records in the GCVE database · Updated August 1, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›