VDB
GCVE-110-OSM-2026-10221
GCVE-110-OSM-2026-10221
Advisory PublishedCVSS 8.8/10
GitHub delivery-front repository for the DPRK Contagious Trader campaign. Presents as a Polymarket/Kalshi arbitrage bot and declares the known-malicious npm package 'bn-eslint.js' (PromptMink infostealer, OSV MAL-2026-6805 / GHSA-r34w-457x-jvh6) as a runtime dependency in package.json, so a victim who clones and runs `npm install` is infected. Near-identical structure to the previously reported tokar821/polymarket-kalshi-arbitrage-bot front (same @polymarket/clob-client + axios + ethers + express + dotenv scaffold). Repo created and pushed same day 2026-07-10 (auto-generated delivery-front pattern). Confirmed live with the malicious dependency present 2026-08-10.
Runtime dependency `bn-eslint.js@^8.0.5` (PromptMink): recursive scan for `.env`/`config.toml`/`id.json`, exfil to *.vercel.app `/api/validate/*`, SSH key injection into ~/.ssh/authorized_keys + `ufw allow 22/tcp`. The package is already catalogued in OSV; this report covers the previously-unreported GitHub delivery vector (the repository itself is not in the OpenSourceMalware database).
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | main @ 2026-07-10 (delivers bn-eslint.js@^8.0.5) (affected) | — |
Aliases
References
Browse GCVE Records
831 records in the GCVE database · Updated September 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.