VDB

GCVE-110-OSM-2026-10262

GCVE-110-OSM-2026-10262
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 10, 2026
This is a DPRK/Lazarus-style supply-chain implant hidden inside a React icon package, not a normal library. This package uses the Nullreceiver method to hide its second stage loader. The attacker model is a stealthy supply-chain operator leveraging a compromised or maliciously published npm package to fetch blockchain-derived targets and execute hidden payloads. The obfuscated payload in `dist/esm/icons/sparkle.mjs` and `dist/esm/icons/sparkles.mjs` uses `eval(r+...)`, `Buffer.from(n,"base64")`, and campaign markers `global['_V']` / `q4FZkxX{!h,Sr3=@`, and deobfuscation recovered hidden IOCs plus an Ethereum address. The code also builds exfil/C2 paths from `eth.blockscout.com`, `1rpc.io`, `eth.drpc.org`, `ethereum-rpc.publicnode.com`, and `eth-mainnet.public.blastapi.io`, while the metadata shows the publisher `brownroger` already has `post-css-transfer` marked malicious. ENTRY dist/cjs/lucide-react.js (main: dist/cjs/lucide-react.js) DESTINATION - 13 exfil (custom-c2, ethereumAddresses) (values recorded in verified_iocs) EXFIL - Network Request in dist/esm/icons/sparkle.mjs: "http.request(" - Network Request in dist/esm/icons/sparkles.mjs: "http.request(" OBFUSCATION - Decoded Unicode Escape Content in dist/esm/icons/sparkle.mjs (x20) - Decoded Unicode Escape Content in dist/esm/icons/sparkles.mjs (x20) - IOCs Found in Deobfuscated Code in dist/esm/icons/sparkle.mjs - IOCs Found in Deobfuscated Code in dist/esm/icons/sparkles.mjs - Whitespace-Padded Hidden Payload in dist/esm/icons/sparkle.mjs: "; global" - Dynamic Base64 Decoding in dist/esm/icons/sparkle.mjs: "Buffer.from(n,"base64")" - Whitespace-Padded Hidden Payload in dist/esm/icons/sparkles.mjs: "; global" - Dynamic Base64 Decoding in dist/esm/icons/sparkles.mjs: "Buffer.from(n,"base64")" (+5 more) ADDITIONAL FINDINGS - Global Require Alias in dist/esm/icons/sparkle.mjs: "global['r']=require" - Campaign marker: PolinRider in dist/esm/icons/sparkle.mjs: "global['_V']" - Campaign marker: nullreceiver in [deobfuscated] dist/esm/icons/sparkle.mjs: "q4FZkxX{!h,Sr3=@" - Dynamic Code Execution in dist/esm/icons/sparkle.mjs: "eval(r+" - Publisher Has Other Malicious Packages - Rapid Version Publishing PAYLOAD FILES dist/esm/icons/sparkle.mjs (+ dist/esm/icons/sparkles.mjs)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowniconova-reactall (affected)

References

advisory
vendor

Browse GCVE Records

474 records in the GCVE database · Updated August 27, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›