VDB

GCVE-110-OSM-2026-10604

GCVE-110-OSM-2026-10604
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published August 16, 2026
One of several dozen malicious npm packages published in a coordinated scripted session on August 16, 2026, targeting six popular JavaScript libraries by name using typos, transpositions, and plausible `-core`/`-lib`/`-cli` suffixes. All packages share identical functional code, confirming a single operator. Executes at install time via `postinstall` hook — no import required. Windows-targeted infostealer; Linux/macOS receive telemetry only. The XOR key (`stf2026`), Rust loader fingerprint, and `gofile[.]io` exfiltration pattern overlap with the StubMaker campaign — this is likely the same threat actor. See https://opensourcemalware.com/?search=%23stubmaker for related OSM records.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowntypecript-coreall (affected)

References

vendor

Browse GCVE Records

1,469 records in the GCVE database · Updated September 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›