VDB

GCVE-110-OSM-2026-10221

GCVE-110-OSM-2026-10221
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published August 11, 2026
GitHub delivery-front repository for the DPRK Contagious Trader campaign. Presents as a Polymarket/Kalshi arbitrage bot and declares the known-malicious npm package 'bn-eslint.js' (PromptMink infostealer, OSV MAL-2026-6805 / GHSA-r34w-457x-jvh6) as a runtime dependency in package.json, so a victim who clones and runs `npm install` is infected. Near-identical structure to the previously reported tokar821/polymarket-kalshi-arbitrage-bot front (same @polymarket/clob-client + axios + ethers + express + dotenv scaffold). Repo created and pushed same day 2026-07-10 (auto-generated delivery-front pattern). Confirmed live with the malicious dependency present 2026-08-10. Runtime dependency `bn-eslint.js@^8.0.5` (PromptMink): recursive scan for `.env`/`config.toml`/`id.json`, exfil to *.vercel.app `/api/validate/*`, SSH key injection into ~/.ssh/authorized_keys + `ufw allow 22/tcp`. The package is already catalogued in OSV; this report covers the previously-unreported GitHub delivery vector (the repository itself is not in the OpenSourceMalware database).

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownmain @ 2026-07-10 (delivers bn-eslint.js@^8.0.5) (affected)

Browse GCVE Records

831 records in the GCVE database · Updated September 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›