VDB

GCVE-110-OSM-2026-10383

GCVE-110-OSM-2026-10383
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 13, 2026
This package is a typosquat of the legitimate postcss-initial library, injecting a heavily obfuscated (obfuscator.io, 1621 hex variable names) payload hidden after 600+ whitespace characters inside what appears to be a normal PostCSS plugin entrypoint. The deobfuscated payload bears two confirmed DPRK/Lazarus campaign markers: 'q4FZkxX{!h,Sr3=@' (nullreceiver campaign) and 'global[\'_V\']' (PolinRider campaign). The malicious code queries multiple Ethereum JSON-RPC endpoints (eth.blockscout.com, 1rpc.io, eth.drpc.org, ethereum-rpc.publicnode.com, eth-mainnet.public.blastapi.io) and contains an Ethereum address '0xa322e5f3d311d3080e6f0121063e9adc2490ef1a' classified as exfil, consistent with a cryptocurrency theft payload that enumerates blockchain transaction data. The use of global['r']=require to alias require for obfuscated calls, child_process spawn, and zlib decompression routines strongly indicates a multi-stage loader consistent with Contagious Interview / Lazarus Group tooling. ENTRY index.js (default-index: index.js) DESTINATION - 1 exfil (ethereumAddresses) - 13 fetched-payload (deobfuscated) (values recorded in verified_iocs) OBFUSCATION - IOCs Found in Deobfuscated Code in index.js - Whitespace-Padded Hidden Payload in index.js: "; global" - Obfuscation (osm-deobfuscator): obfuscator-io in index.js - String Array Obfuscation in index.js: "['6f0121063e','Mozilla/5.','vsVto','BoIAd','GGFaB','ZFXMR','createInfl','cpUBI',..." - Unicode Escape Obfuscation in index.js: "\u0068\u0074\u0074\u0070\u0073\u003A" - Decoded Unicode Escape Content in index.js - Obfuscation patterns: hexVariables in index.js - recovered 2 ipv4, 7 urls, 13 domains, 1 ethereumAddresses, 13 _domainCandidates from decoded/deobfuscated content ADDITIONAL FINDINGS - Global Require Alias in index.js: "global['r']=require" - Campaign marker: nullreceiver in [deobfuscated] index.js: "q4FZkxX{!h,Sr3=@" - Campaign marker: PolinRider in [deobfuscated] index.js: "global['_V']" - Brand New Package PAYLOAD FILES index.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownpostcss-initialize-pluginall (affected)

Browse GCVE Records

3,521 records in the GCVE database · Updated September 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›