VDB
GCVE-110-OSM-2026-10261
GCVE-110-OSM-2026-10261
Advisory PublishedCVSS 9.6/10
This package is a legitimate package, but the maintainer was compromised by DPRK threat actors and one malicious version was published: 1.0.1786316795
A malicious JavaScript payload was attached to the end of the lang/gdscript.js file. This is the classic PolinRider tradecraft. This malicious JavaScript installs a persistence infostealer, cryptostealer and RAT.
ENTRY
bin/install.js (bin: bin/install.js)
EXFIL
- Git Configuration Access in .github/workflows/auto-declaudeify.yml: "git config user.name"
- Git Configuration Access in .github/workflows/publish.yml: "git config user.name"
- Network Request in lang/gdscript.js: "http.request("
- System Information Collection in lang/gdscript.js: "process.platform"
- System Information Collection in test.js: "process.platform"
ADDITIONAL FINDINGS
- Download Execute Delete Pattern in lang/gdscript.js: "writeFileSync(tmp, `extends SceneTree\nfunc _init():\n${indented}\n\tquit()\n`);..."
- Campaign marker: PolinRider in skills/godot-dev/assets/repl_bridge.gd: "ss_info"
- Shell Command Execution in lang/gdscript.js: "require('child_process')"
PAYLOAD FILES
lang/gdscript.js (+ test.js)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | godot-kit | 1.0.1786316795 (affected) | — |
Aliases
Browse GCVE Records
825 records in the GCVE database · Updated September 1, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.