VDB
GCVE-110-OSM-2026-10619
GCVE-110-OSM-2026-10619
Advisory PublishedCVSS 9.6/10
Typosquatting package impersonating `typescript`. One of 37 malicious npm packages published in a coordinated scripted session on August 16, 2026, targeting six popular JavaScript libraries by name using typos, transpositions, and plausible `-core`/`-lib`/`-cli` suffixes. All packages share identical functional code, confirming a single operator. Executes at install time via `postinstall` hook — no import required. Windows-targeted infostealer; Linux/macOS receive telemetry only. The XOR key (`stf2026`), Rust loader fingerprint, and `gofile[.]io` exfiltration pattern overlap with the StubMaker campaign — this is likely the same threat actor. See https://opensourcemalware.com/?search=%23stubmaker for related OSM records.
`postinstall` script decodes embedded config via repeated-key XOR (key: `stf2026`), then beacons victim IP and platform via HTTP POST to `193[.]70[.]34[.]101:20099/vote`. On Windows (including WSL), downloads a Rust-based loader (22 MB, SHA256: `6f088ade49456db2422c3edfbb9998f4a3e9cce7c4c00a7279fb45d672a82b7d`) from `github[.]com/bebraz1/qPzM50V1AKG0rVlH/releases/download/null/main[.]exe`, which decrypts and maps an embedded 64-bit Go infostealer (SHA256: `1afff50ca4064310d3492c652e1c3168216dcb42063e0b26c223038db46b8731`). Steals browser credentials, cookies, session tokens, payment card data, cryptocurrency wallet files and seed phrases, and Telegram `tdata`. Exfiltrates via encrypted ZIP to `gofile[.]io`.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | tyepescript-cli | all (affected) | — |
Browse GCVE Records
69,369 records in the GCVE database · Updated August 25, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.