VDB

GCVE-110-OSM-2026-10222

GCVE-110-OSM-2026-10222
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published August 11, 2026
GitHub delivery-front repository for the DPRK Contagious Trader campaign. Presents as a Polymarket copy-trading bot (NestJS) and declares the known-malicious npm package 'async-mutex-lock' (typosquat of the legitimate 'async-mutex', OSV MAL-2026-12513 / GHSA-vwr9-j5fc-42fq, severity critical) as a runtime dependency in package.json, so a victim who clones and runs `npm install` is infected. Repo created and pushed same day 2026-07-22 (auto-generated delivery-front pattern). Confirmed live with the malicious dependency present 2026-08-10. Runtime dependency `async-mutex-lock@^5.3.1` — a typosquat of the popular `async-mutex` package (OSV MAL-2026-12513, critical). The package is already catalogued in OSV/OSM; this report covers the previously-unreported GitHub delivery vector (the repository itself is not in the OpenSourceMalware database). NOTE: the repo's devDependencies also include eslint-config-prettier and eslint-plugin-prettier — these are LEGITIMATE packages at normal versions and are NOT part of the malice; they are excluded from this report.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownmain @ 2026-07-22 (delivers async-mutex-lock@^5.3.1) (affected)

Browse GCVE Records

390 records in the GCVE database · Updated August 26, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›