VDB
GCVE-110-OSM-2026-10604
GCVE-110-OSM-2026-10604
Advisory PublishedCVSS 8.8/10
One of several dozen malicious npm packages published in a coordinated scripted session on August 16, 2026, targeting six popular JavaScript libraries by name using typos, transpositions, and plausible `-core`/`-lib`/`-cli` suffixes. All packages share identical functional code, confirming a single operator. Executes at install time via `postinstall` hook — no import required. Windows-targeted infostealer; Linux/macOS receive telemetry only. The XOR key (`stf2026`), Rust loader fingerprint, and `gofile[.]io` exfiltration pattern overlap with the StubMaker campaign — this is likely the same threat actor. See https://opensourcemalware.com/?search=%23stubmaker for related OSM records.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | typecript-core | all (affected) | — |
Browse GCVE Records
1,469 records in the GCVE database · Updated September 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.