VDB
GCVE-110-OSM-2026-10222
GCVE-110-OSM-2026-10222
Advisory PublishedCVSS 8.8/10
GitHub delivery-front repository for the DPRK Contagious Trader campaign. Presents as a Polymarket copy-trading bot (NestJS) and declares the known-malicious npm package 'async-mutex-lock' (typosquat of the legitimate 'async-mutex', OSV MAL-2026-12513 / GHSA-vwr9-j5fc-42fq, severity critical) as a runtime dependency in package.json, so a victim who clones and runs `npm install` is infected. Repo created and pushed same day 2026-07-22 (auto-generated delivery-front pattern). Confirmed live with the malicious dependency present 2026-08-10.
Runtime dependency `async-mutex-lock@^5.3.1` — a typosquat of the popular `async-mutex` package (OSV MAL-2026-12513, critical). The package is already catalogued in OSV/OSM; this report covers the previously-unreported GitHub delivery vector (the repository itself is not in the OpenSourceMalware database). NOTE: the repo's devDependencies also include eslint-config-prettier and eslint-plugin-prettier — these are LEGITIMATE packages at normal versions and are NOT part of the malice; they are excluded from this report.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | main @ 2026-07-22 (delivers async-mutex-lock@^5.3.1) (affected) | — |
Aliases
References
Browse GCVE Records
390 records in the GCVE database · Updated August 26, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.