VDB

GCVE-110-OSM-2026-10261

GCVE-110-OSM-2026-10261
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 11, 2026
This package is a legitimate package, but the maintainer was compromised by DPRK threat actors and one malicious version was published: 1.0.1786316795 A malicious JavaScript payload was attached to the end of the lang/gdscript.js file. This is the classic PolinRider tradecraft. This malicious JavaScript installs a persistence infostealer, cryptostealer and RAT. ENTRY bin/install.js (bin: bin/install.js) EXFIL - Git Configuration Access in .github/workflows/auto-declaudeify.yml: "git config user.name" - Git Configuration Access in .github/workflows/publish.yml: "git config user.name" - Network Request in lang/gdscript.js: "http.request(" - System Information Collection in lang/gdscript.js: "process.platform" - System Information Collection in test.js: "process.platform" ADDITIONAL FINDINGS - Download Execute Delete Pattern in lang/gdscript.js: "writeFileSync(tmp, `extends SceneTree\nfunc _init():\n${indented}\n\tquit()\n`);..." - Campaign marker: PolinRider in skills/godot-dev/assets/repl_bridge.gd: "ss_info" - Shell Command Execution in lang/gdscript.js: "require('child_process')" PAYLOAD FILES lang/gdscript.js (+ test.js)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowngodot-kit1.0.1786316795 (affected)

References

advisory
vendor

Browse GCVE Records

825 records in the GCVE database · Updated September 1, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›