VDB

GCVE-110-OSM-2026-10134

GCVE-110-OSM-2026-10134
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published August 10, 2026
GitHub delivery-front repository for the DPRK Contagious Trader campaign. Presents as a Polymarket/Kalshi arbitrage trading bot and declares the known-malicious npm package 'bn-eslint.js' (PromptMink infostealer, OSV MAL-2026-6805 / GHSA-r34w-457x-jvh6) as a runtime dependency in package.json, so a victim who clones and runs `npm install` is infected. Repo created and last pushed 2026-07-15 (single-day push pattern typical of auto-generated delivery fronts). Repo confirmed still live with the malicious dependency present as of 2026-08-09. Dependency `bn-eslint.js@^8.0.5` (PromptMink): recursive scan for `.env`/`config.toml`/`id.json`, exfil to *.vercel.app `/api/validate/*`, SSH key injection into ~/.ssh/authorized_keys + `ufw allow 22/tcp`. Deceptive export aliases (check_if_matches/search_hashes/verify_hash). The package is already catalogued in OSV; this report covers the previously-unreported GitHub delivery vector.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownmain @ 2026-07-15 (delivers bn-eslint.js@^8.0.5) (affected)

Browse GCVE Records

67,407 records in the GCVE database · Updated August 11, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›