VDB

GCVE-110-OSM-2025-820

GCVE-110-OSM-2025-820
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published November 1, 2025
Malicious GitHub repository tied to Operation RepoGhost, a Russian-linked campaign masquerading as legitimate AI, cybersecurity, cryptocurrency, or vulnerability-research tooling. When the repo's advertised script is executed, it silently launches a next-stage payload chain that ultimately deploys a custom Go-based Windows infostealer (earlier iterations delivered CountLoader on Windows and Nova macOS infostealer). The malicious code is embedded directly inside the same script the victim runs to use the advertised tool, so infection happens as a byproduct of normal use with no separate download. Infection chain: repo script invokes subprocess.Popen calling scriptrunner.exe (App-V living-off-the-land binary) with -appvscript to proxy-execute powershell.exe, which pulls a Pastebin-hosted stager that fetches main.exe (Go-based infostealer) and executes it. Earlier commits delivered a Base64-wrapped Python multi-platform dropper (Peravi / Nova macOS branch + Go infostealer Windows branch). Go infostealer capabilities: browser sessions/credentials, Discord tokens, Telegram sessions, Steam sessions, cryptocurrency wallets. Loads an obfuscated .NET assembly (~168KB, internal name 'mid4') directly into memory. Skips execution on ru-RU locale systems. C2: 194.102.104.141:22310. Related staging: 172.237.119.163:8000, 85.120.255.252:8000, 2.27.63.236:8000, pypi3.cc, py-installer.com.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)

Browse GCVE Records

753 records in the GCVE database · Updated September 1, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›