VDB

GCVE-110-OSM-2026-10240

GCVE-110-OSM-2026-10240
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 12, 2026
Package is a typo squat of the legitimate tailwind-merge package. Unfortunatly, this package is part of a North Korean cluster of NPM packages delivering otter cookie malware. The package.json file installs a git repo from https://github.com/stardev0914/tailwind-magic, which then downloads a multi-stage otter cookie malware.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowntailwind-magicall (affected)

References

advisory
vendor

Browse GCVE Records

69,226 records in the GCVE database · Updated August 24, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›