VDB

GCVE-110-OSM-2025-441

GCVE-110-OSM-2025-441
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published November 13, 2025
DPRK-aligned 'Contagious Interview' campaign repository. Trojanized job-interview code project whose config/.env embeds a base64-encoded URL pointing at a legitimate JSON storage service (JSON Keeper / JSONsilo / npoint.io) that serves an obfuscated BeaverTail loader, leading to InvisibleFerret RAT. Delivered via fake LinkedIn recruiters. Malicious base64-encoded C2 URL embedded in the repository's config/.env file. Decodes to a JSON storage service URL serving the BeaverTail loader. XOR key used in later Pastebin stages: !!!HappyPenguin1950!!!

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)

Browse GCVE Records

75,792 records in the GCVE database · Updated August 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›