VDB
GCVE-110-OSM-2025-825
GCVE-110-OSM-2025-825
Advisory PublishedCVSS 8.8/10
Malicious GitHub repository tied to Operation RepoGhost, a Russian-linked campaign masquerading as legitimate AI, cybersecurity, cryptocurrency, or vulnerability-research tooling. When the repo's advertised script is executed, it silently launches a next-stage payload chain that ultimately deploys a custom Go-based Windows infostealer (earlier iterations delivered CountLoader on Windows and Nova macOS infostealer). The malicious code is embedded directly inside the same script the victim runs to use the advertised tool, so infection happens as a byproduct of normal use with no separate download.
Infection chain: repo script invokes subprocess.Popen calling scriptrunner.exe (App-V living-off-the-land binary) with -appvscript to proxy-execute powershell.exe, which pulls a Pastebin-hosted stager that fetches main.exe (Go-based infostealer) and executes it. Earlier commits delivered a Base64-wrapped Python multi-platform dropper (Peravi / Nova macOS branch + Go infostealer Windows branch).
Go infostealer capabilities: browser sessions/credentials, Discord tokens, Telegram sessions, Steam sessions, cryptocurrency wallets. Loads an obfuscated .NET assembly (~168KB, internal name 'mid4') directly into memory. Skips execution on ru-RU locale systems.
C2: 194.102.104.141:22310. Related staging: 172.237.119.163:8000, 85.120.255.252:8000, 2.27.63.236:8000, pypi3.cc, py-installer.com.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Browse GCVE Records
825 records in the GCVE database · Updated September 1, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.