VDB

GCVE-110-OSM-2026-10475

GCVE-110-OSM-2026-10475
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 14, 2026
Package.json describes the package as 'Static assets distribution', but the shipped HTML/JS is an iOS-version-gated payload loader. js/index.js unconditionally appends a <script> tag loading https://cdn.jsdelivr.net/npm/@cdnshell/loader/a188ps10.js (an unrelated npm scope, no integrity attribute) into the page. 01_iframe.js gates on an iOS user-agent and appends a hidden 0x0 iframe to https://unpkg.com/@themepack/dark/ah3zhsl.html?t=<timestamp> (also an unrelated scope). 02_probe.js computes the iOS build number and selects per-iOS-version 'lanes' (iOS 15.2-17.x) executed inside a Worker; in-code Chinese comments explicitly describe primitive injection, sandbox status, and running attack code via Worker ('真实原语注入模块经 Worker 跑攻击代码'), with gate-exit branches for Mac desktop / older versions. Non-iOS visitors are silently ignored; iOS visitors receive the hidden iframe delivering remote HTML. The publisher scope (@demopack) is unrelated to the scopes hosting the loaded code (@cdnshell, @themepack). A developer who integrates these assets into their site would serve a drive-by iOS exploit chain to their end users. There are no lifecycle scripts, so the harm is not to the npm installer directly, but to the visitors of any site that ships these assets; the advertised purpose is a cover story for browser-side exploit delivery. Judge assessment: This looks like a browser-side payload loader rather than a static assets package: the entrypoint `js/index.js` unconditionally injects a remote script from `https://cdn.jsdelivr.net/npm/@cdnshell/loader@0.0.15/a140ulh5.js`, and the shipped code explicitly describes an execution chain in Chinese comments. The OSV advisory is strongly corroborated by the actual files, especially `js/index.js` and the referenced `01_iframe.js`/`02_probe.js` chain that gates on iOS and loads remote content, which matches a drive-by delivery model for end users of a site that installs this package. The attacker model is a publisher disguising a malicious loader as `Static assets distribution` to seed downstream websites with a remote exploit or payload chain, not an accidental utility library. The brand-new publisher account and lack of repository further support malicious intent rather than a legitimate frontend asset bundle. ENTRY js/index.js (default-index: index.js) ADDITIONAL FINDINGS - Brand New Package - Very New NPM Publisher Account

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@demopack/wwwall (affected)

References

advisory
vendor

Browse GCVE Records

831 records in the GCVE database · Updated September 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›